APT-C-26(Lazarus)组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析
2026-06-03 • Qihoo360 • Analysis of APT-C-26 (Lazarus) Attack Campaign Exploiting CVE-2025-55182 and Copperhedge Components •
Lazarus is assessed to have weaponized CVE-2025-55182, a React Server Components insecure deserialization flaw, in a Windows executable that scans target lists and attempts bulk exploitation for initial access. The intrusion chain pairs the exploit tool with MultiRelay for internal movement, Akagi64 for UAC bypass, and rundll32 execution of a Copperhedge Loader that decrypts and runs a Copperhedge Backdoor in memory. The backdoor creates the MsSecurityObj mutex, stores encrypted configuration in a file or registry location, collects host and network details, and communicates with C2 using HTTP parameters followed by ChaCha20, XOR, and Base64 protected traffic. Its command set supports reconnaissance, command execution, file upload and download, CAB archive staging, process control, timestamp manipulation, configuration updates, and reflective payload loading. The report links the activity to Lazarus based on Copperhedge's historical association, overlap with known CVE-2025-55182 exploitation patterns, and likely targeting of financial or blockchain infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 206.71.148.38 | 2026-06-03 | 2026-06-03 |
| URL | https://www.magazineschool.co.k… | 2026-06-03 | 2026-06-03 |
| HASH | 0677555769e4b64cc084dcc132048144 | 2026-06-03 | 2026-06-03 |
| HASH | e6569de917f84422439765b3a67ca971 | 2026-06-03 | 2026-06-03 |
| HASH | bfd66efdcafb9d24ed9f0e2f733b129c | 2026-06-03 | 2026-06-03 |
| HASH | 2175449ed1c275f2cb2490094d7aabf8 | 2026-06-03 | 2026-06-03 |
| HASH | cb7c15fc9c07a3db79f35d64efc2fc73 | 2026-06-03 | 2026-06-03 |
| HASH | 72aa61fa53e9caeee9d2993312587b46 | 2026-06-03 | 2026-06-03 |
| HASH | 3c922758c200100840f77bc691ef78ce | 2026-06-03 | 2026-06-03 |
| HASH | a4d2759e6fc0b6fe5fe221a8bd75c769 | 2026-06-03 | 2026-06-03 |
| HASH | 9174ecb742b82a0bc4c002b82cc13fa0 | 2026-06-03 | 2026-06-03 |
| HASH | 246e5b07824f131dc4cb1fad35f8f763 | 2026-06-03 | 2026-06-03 |
| HASH | e3d66a422a81ed40dbd6bb6abd4a3e54 | 2026-06-03 | 2026-06-03 |
| HASH | 324f7ef1b7aeb9258e06dabe99a8948f | 2026-06-03 | 2026-06-03 |
| HASH | f85a05aa9781848e2a9e3f42f0c3418a | 2026-06-03 | 2026-06-03 |
| HASH | 2e5fafffc9970527c1bbd5262da52f59 | 2026-06-03 | 2026-06-03 |