Another Lazarus Injector

2019-10-02 Norfolk

https://norfolkinfosec.com/another-lazarus-injector/

Thumbnail for Another Lazarus Injector

The follow-up Lazarus Injector analysis covers a signed malware tool uploaded to VirusTotal that appears related to earlier Lazarus tooling but behaves differently from the first injector. The file expects command-line parameters for operational mode and target process ID, supporting injection or ejection behavior rather than simply loading a supplied payload into Explorer. The author notes strong resemblance to tooling described in a FASTCash AIX malware report, suggesting a Windows counterpart for similar operational needs. The post provides hashes, signing context, and behavior details for detecting Lazarus injection utilities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 89081f2e14e9266de8c042629b764926 2019-10-02 2020-08-05
HASH 39cbad3b2aac6298537a85f0463453d… 2019-10-02 2020-03-09
HASH 730c1b9e950932736fc4b02cbdb4e4e… 2019-10-02 2019-10-02

Related Actors

Related Reports

« Back