APT-C-26(Lazarus)组织伪造电商组件攻击活动分析报告

2022-07-15 Qihoo360 Analysis report on an APT-C-26 (Lazarus) campaign using fake e-commerce components

https://mp.weixin.qq.com/s/USitU4jAg9y2XkQxbwcAPQ

Thumbnail for APT-C-26(Lazarus)组织伪造电商组件攻击活动分析报告

360 attributed a 2022 campaign to Lazarus/APT-C-26 that used fake Alibaba-related components to target specific users, with observed victimology including South Korean software company Hancom Secure. The loader registered persistence through counterfeit components such as alibabaprotect.db and alibabaconf.bat, then executed an HttpUploader payload associated with the NukeSped family. The malware passed the C2 address and local upload path as runtime parameters, decrypted an in-memory second stage, and attempted to read and upload files such as c:\ProgramData\Alibaba\cfpconfg.out. Reported infrastructure included stracarrara[.]org and namchuncheon.co[.]kr, and the campaign matters because it combined targeted collection, parameter-separated configuration, and fileless follow-on execution to reduce exposure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b25f1917d45fd0db2c82feb239b9e69e 2022-07-15 2022-07-15
URL http://www.stracarrara.org/publ… 2022-07-15 2022-07-15
URL http://www.stracarrara.org/publ… 2022-07-15 2022-07-15

Related Actors

Related Reports

« Back