Andariel’s “Jupiter” malware and the case of the curious C2
2023-05-16 • DCSO •
https://medium.com/@DCSO_CyTec/andariels-jupiter-malware-and-the-case-of-the-curious-c2-dbfe29f57499
DCSO describes “Jupiter,” a previously little-documented PureBasic malware family it attributes to Andariel, a North Korean Lazarus subgroup. The malware has appeared sporadically since 2020, including an OSPREY-signed sample tied to an attempted attack on a German medical or pharmaceutical company and a sample later referenced in CISA’s H0lygh0st ransomware advisory. A fresh 2023 sample contained C2 configuration suggesting possible abuse of India’s National Institute of Virology web presence, although DCSO could not prove the server was actively compromised. Jupiter provides basic download and shell-command execution functions, with command output returned to C2, and the targeting context aligns with DPRK interest in healthcare and medical research during and after the COVID-19 pandemic.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | c28bb61de4a6ad1c5e225ad9ec2eaf4… | 2023-05-16 | 2024-07-25 |
| HASH | 34d5a5d8bec893519f204b573c33d54… | 2023-05-16 | 2024-07-25 |
| HASH | aa29bf4292b68d197f4d8ca026b97ec… | 2023-05-16 | 2024-07-25 |
| HASH | 772b06f34facf6a2ce351b8679ff957… | 2023-05-16 | 2024-07-25 |
| HASH | 9a5504dcfb7e664259bfa58c46cfd33… | 2023-05-16 | 2024-07-25 |
| HASH | 664f8d19af3400a325998b332343a93… | 2023-05-16 | 2024-07-25 |
| IPv4 | 40.121.90.194 | 2022-09-08 | 2023-09-12 |
| URL | http://projectcell.niv.co.in/no… | 2023-05-16 | 2023-05-16 |
| URL | http://sora.bz/xoops_root_path/… | 2023-05-16 | 2023-05-16 |
| URL | http://sora.bz/xoops_root_path/… | 2023-05-16 | 2023-05-16 |
| URL | http://eflow.co.kr/member_image… | 2023-05-16 | 2023-05-16 |
| DOMAIN | niv.co | 2023-05-16 | 2023-05-16 |
| DOMAIN | ns.iknowledgefactory.com | 2023-05-16 | 2023-05-16 |
| DOMAIN | projectcell.niv.co | 2023-05-16 | 2023-05-16 |
| DOMAIN | eflow.co.kr | 2023-05-16 | 2023-05-16 |
| DOMAIN | projectcell.niv.co.in | 2023-05-16 | 2023-05-16 |
| DOMAIN | sora.bz | 2023-05-16 | 2023-05-16 |
| DOMAIN | niv.icmr.org | 2023-05-16 | 2023-05-16 |
| IPv4 | 103.73.189.76 | 2023-05-16 | 2023-05-16 |
| IPv4 | 3.89.226.234 | 2023-05-16 | 2023-05-16 |
| IPv4 | 173.249.44.87 | 2023-05-16 | 2023-05-16 |
| IPv4 | 173.249.33.80 | 2023-05-16 | 2023-05-16 |