APT-C-26(Lazarus)组织使用伪造VNC软件的攻击活动分析

2023-06-26 Qihoo360 Analysis of attack activities of APT-C-26 (Lazarus) organization using fake VNC software

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247492789&idx=1&sn=a991e6c5ed7388515d75f02e9c33428f&chksm=f9c1d7bcceb65eaa504f5b1e56ad0f31d2aee62623102d2a8f80fcd7c203047691c7f654ae45&scene=178&cur_album_id=1915287066892959748#rd

Thumbnail for APT-C-26(Lazarus)组织使用伪造VNC软件的攻击活动分析

360 Advanced Threat Research Institute attributes a campaign using fake ComcastVNC software to APT-C-26/Lazarus with medium confidence, based on alignment with previously reported Lazarus TightVNC and sRDI/BlindingCan tradecraft. The initial archive/ISO delivered ComcastVNC.exe, a legitimate choice.exe abused for DLL sideloading, plus version.dll and portable.dat; execution loaded shellcode and either ran it in a new thread or injected it into iexpress.exe when Kaspersky was present. The chain dropped a modified TightVNC-based ComcastVNC.DAT and a VMProtect-protected BlindingCan/AIRDRY HTTP(S) backdoor that contacted rowdensurname[.]org. The analysis cites matching RTTI artifacts, rich-header similarities, User-Agent and communication-string overlap, RC4/Base64-encrypted C2 traffic, and server-side ASP handling of client identifiers as evidence.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9fff2b059a182e2cb2be604580a911b0 2023-06-26 2023-06-26
URL https://www.rowdensurname.org/s… 2023-06-26 2023-06-26

Related Actors

Related Reports

« Back