APT-C-26(Lazarus)组织利用WinRAR漏洞部署Blank Grabber木马的技术分析
2025-12-12 • Qihoo360 • Technical Analysis of APT-C-26 (Lazarus) Using a WinRAR Vulnerability to Deploy the Blank Grabber Trojan •
360 researchers attribute a malicious archive campaign to APT-C-26/Lazarus, reporting exploitation of WinRAR path traversal CVE-2025-8088 through a file named Pharos.rar. The archive is disguised as a Pharos Automation Bot project and abuses NTFS Alternate Data Stream handling to drop 1.bat into the Windows Startup folder when extracted. The infection chain displays a fake Windows Defender update warning, downloads and runs an obfuscated Python loader from Dropbox, installs Python if needed, adds persistence, and retrieves Tsunami Injector and additional payloads. The final Blank Grabber configuration steals Chromium and Firefox browser data, Discord and Telegram sessions, Wi-Fi credentials, gaming sessions, and seed or private-key material from more than 20 cryptocurrency wallets including MetaMask, Exodus, and Electrum. The cryptocurrency-themed lure and enabled theft functions make the campaign especially relevant to defenders tracking Lazarus operations against crypto users and developers.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 41df3b66ebcfb6e4d4d581d678299041 | 2025-12-12 | 2025-12-12 |
| HASH | faa9dec02bad43b1af68a4194dea8762 | 2025-12-12 | 2025-12-12 |
| HASH | 273af5e2e0130baee7d3b55081be5ad5 | 2025-12-12 | 2025-12-12 |