ClickFix 방식으로 배포되는 라자루스(Lazarus)의 악성코드 분석 보고서_1편

2025-02-11 Nurilab Analysis of Lazarus Malware Distributed via the ClickFix Technique, Part 1

https://blog.naver.com/nurilab1/223756901839

Thumbnail for ClickFix 방식으로 배포되는 라자루스(Lazarus)의 악성코드 분석 보고서_1편

Nurilab analyzes malware distribution that mirrors the Lazarus ClickFix technique, in which a fake CAPTCHA page persuades the victim to copy and run a script through social engineering. The script downloads an rzy.mp3 file from the web server and executes it with mshta, despite the MP3 extension hiding malicious script content. The report follows multiple de-obfuscation and decryption stages that eventually generate a binary and load it into memory, making it relevant for defenders hunting script-driven ClickFix delivery and mshta abuse.

Related Actors

Related Reports

« Back