APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析

2026-06-03 Qihoo360 Analysis of APT-C-26 (Lazarus) Attack Campaign Exploiting CVE-2025-55182 and Copperhedge Components

https://mp.weixin.qq.com/s/3kwDMAXviaE1TUDnkYlqrg

Thumbnail for APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析

Lazarus is assessed to have weaponized CVE-2025-55182, a React Server Components insecure deserialization flaw, in a Windows executable that scans target lists and attempts bulk exploitation for initial access. The intrusion chain pairs the exploit tool with MultiRelay for internal movement, Akagi64 for UAC bypass, and rundll32 execution of a Copperhedge Loader that decrypts and runs a Copperhedge Backdoor in memory. The backdoor creates the MsSecurityObj mutex, stores encrypted configuration in a file or registry location, collects host and network details, and communicates with C2 using HTTP parameters followed by ChaCha20, XOR, and Base64 protected traffic. Its command set supports reconnaissance, command execution, file upload and download, CAB archive staging, process control, timestamp manipulation, configuration updates, and reflective payload loading. The report links the activity to Lazarus based on Copperhedge's historical association, overlap with known CVE-2025-55182 exploitation patterns, and likely targeting of financial or blockchain infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 206.71.148.38 2026-06-03 2026-06-03
URL https://www.magazineschool.co.k… 2026-06-03 2026-06-03
HASH 0677555769e4b64cc084dcc132048144 2026-06-03 2026-06-03
HASH e6569de917f84422439765b3a67ca971 2026-06-03 2026-06-03
HASH bfd66efdcafb9d24ed9f0e2f733b129c 2026-06-03 2026-06-03
HASH 2175449ed1c275f2cb2490094d7aabf8 2026-06-03 2026-06-03
HASH cb7c15fc9c07a3db79f35d64efc2fc73 2026-06-03 2026-06-03
HASH 72aa61fa53e9caeee9d2993312587b46 2026-06-03 2026-06-03
HASH 3c922758c200100840f77bc691ef78ce 2026-06-03 2026-06-03
HASH a4d2759e6fc0b6fe5fe221a8bd75c769 2026-06-03 2026-06-03
HASH 9174ecb742b82a0bc4c002b82cc13fa0 2026-06-03 2026-06-03
HASH 246e5b07824f131dc4cb1fad35f8f763 2026-06-03 2026-06-03
HASH e3d66a422a81ed40dbd6bb6abd4a3e54 2026-06-03 2026-06-03
HASH 324f7ef1b7aeb9258e06dabe99a8948f 2026-06-03 2026-06-03
HASH f85a05aa9781848e2a9e3f42f0c3418a 2026-06-03 2026-06-03
HASH 2e5fafffc9970527c1bbd5262da52f59 2026-06-03 2026-06-03

Related Actors

Related Reports

« Back