APT-C-26(Lazarus)组织利用WinRAR漏洞部署Blank Grabber木马的技术分析

2025-12-12 Qihoo360 Technical Analysis of APT-C-26 (Lazarus) Using a WinRAR Vulnerability to Deploy the Blank Grabber Trojan

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247507693&idx=1&sn=e73e1cca5af2ee80c3037daa1dbd2ab1

Thumbnail for APT-C-26(Lazarus)组织利用WinRAR漏洞部署Blank Grabber木马的技术分析

360 researchers attribute a malicious archive campaign to APT-C-26/Lazarus, reporting exploitation of WinRAR path traversal CVE-2025-8088 through a file named Pharos.rar. The archive is disguised as a Pharos Automation Bot project and abuses NTFS Alternate Data Stream handling to drop 1.bat into the Windows Startup folder when extracted. The infection chain displays a fake Windows Defender update warning, downloads and runs an obfuscated Python loader from Dropbox, installs Python if needed, adds persistence, and retrieves Tsunami Injector and additional payloads. The final Blank Grabber configuration steals Chromium and Firefox browser data, Discord and Telegram sessions, Wi-Fi credentials, gaming sessions, and seed or private-key material from more than 20 cryptocurrency wallets including MetaMask, Exodus, and Electrum. The cryptocurrency-themed lure and enabled theft functions make the campaign especially relevant to defenders tracking Lazarus operations against crypto users and developers.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 41df3b66ebcfb6e4d4d581d678299041 2025-12-12 2025-12-12
HASH faa9dec02bad43b1af68a4194dea8762 2025-12-12 2025-12-12
HASH 273af5e2e0130baee7d3b55081be5ad5 2025-12-12 2025-12-12

Related Actors

Related Reports

« Back