APT-C-26(Lazarus)组织使用武器化的IPMsg软件的攻击活动分析

2024-12-26 Qihoo360 Cyber threat report on APT-C-26, IPMsg

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247505438&idx=1&sn=cf1947c7af6581f4a66460ae6d14dc2f

Thumbnail for APT-C-26(Lazarus)组织使用武器化的IPMsg软件的攻击活动分析

The report analyzes an APT-C-26/Lazarus campaign that delivered a weaponized IPMsg installer to targets. When executed, the installer dropped a malicious DLL while also launching the legitimate IPMsg Installer 5.6.18.0 to reduce user suspicion. The DLL chain decrypted and loaded multiple additional DLLs, used validation checks to hinder standalone sandbox execution, communicated with C2 over HTTP using encoded parameters and random strings, validated downloaded payloads by MD5, decrypted them with HC-256, and ultimately established a backdoor capable of fetching and executing further payloads.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a7b23cd8b09a3ce918a77de355e9d3e5 2024-12-26 2025-05-16
URL https://cryptocopedia.com/upgra… 2024-12-26 2025-05-16
DOMAIN cryptocopedia.com 2024-07-08 2025-05-16
URL https://cryptocopedia.com/explo… 2024-12-26 2024-12-26

Related Actors

Related Reports

« Back