Analysis of Lazarus malware abusing Non-ActiveX Module in South Korea
2021-07-08 • S2W •
S2W analyzes a Lazarus-linked signed DLL disguised as the open-source Notepad++ ComparePlus plugin and apparently tailored to systems with a South Korean Non-ActiveX security component installed. The malware checked for INITECH/INISAFE Web EX Client files and SCSKAppLink.dll before loading itself through comp.exe, using DLL injection to force execution. Its final behavior was to download an additional payload from compromised Korean web infrastructure, decrypt it with RC5, and execute it in memory; observed URLs included grandgolf.co.kr, namchuncheon.co.kr, and kdone.co.kr paths with product_field=racket. The report ties the sample to Lazarus through similarities in string-decoding logic and the group's recurring use of normal-file masquerading, signed components, and domestic Korean distribution sites.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b3a8c88297daecdb9b0ac54a3c107797 | 2021-07-08 | 2023-04-12 |
| HASH | a881c9f40c1a5be3919cafb2ebe2bb5… | 2021-07-08 | 2022-04-14 |
| HASH | 61367c3a1d4c9ccaee568157bc4cf2f… | 2021-07-08 | 2021-07-08 |
| HASH | 98151ba9f3e0a55bba16c58428b3a178 | 2021-07-08 | 2021-07-08 |
| HASH | 46660f562fe01b5df0e1ac03dd44b4c… | 2021-07-08 | 2021-07-08 |