APT-C-26(Lazarus)组织使用伪造VNC软件的攻击活动分析
2023-06-26 • Qihoo360 • Analysis of attack activities of APT-C-26 (Lazarus) organization using fake VNC software •
360 Advanced Threat Research Institute attributes a campaign using fake ComcastVNC software to APT-C-26/Lazarus with medium confidence, based on alignment with previously reported Lazarus TightVNC and sRDI/BlindingCan tradecraft. The initial archive/ISO delivered ComcastVNC.exe, a legitimate choice.exe abused for DLL sideloading, plus version.dll and portable.dat; execution loaded shellcode and either ran it in a new thread or injected it into iexpress.exe when Kaspersky was present. The chain dropped a modified TightVNC-based ComcastVNC.DAT and a VMProtect-protected BlindingCan/AIRDRY HTTP(S) backdoor that contacted rowdensurname[.]org. The analysis cites matching RTTI artifacts, rich-header similarities, User-Agent and communication-string overlap, RC4/Base64-encrypted C2 traffic, and server-side ASP handling of client identifiers as evidence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 9fff2b059a182e2cb2be604580a911b0 | 2023-06-26 | 2023-06-26 |
| URL | https://www.rowdensurname.org/s… | 2023-06-26 | 2023-06-26 |