ClickFix 방식으로 배포되는 라자루스(Lazarus)의 악성코드 분석 보고서_1편
2025-02-11 • Nurilab • Analysis of Lazarus Malware Distributed via the ClickFix Technique, Part 1 •
Nurilab analyzes malware distribution that mirrors the Lazarus ClickFix technique, in which a fake CAPTCHA page persuades the victim to copy and run a script through social engineering. The script downloads an rzy.mp3 file from the web server and executes it with mshta, despite the MP3 extension hiding malicious script content. The report follows multiple de-obfuscation and decryption stages that eventually generate a binary and load it into memory, making it relevant for defenders hunting script-driven ClickFix delivery and mshta abuse.
Related Actors
Related Reports
Shares tags: Lazarus, ClickFix • Same author: Nurilab • Published within a week
2025-02-07 •
80% Match
#ContagiousInterview
#Lazarus
#ClickFix
#T1082
#T1041
#T1555
#T1056.001
#T1027
#T1204.002
#T1555.003
#T1027.002
#T1564.001
#T1016
#T1033
#T1546.008
Shares tags: Lazarus, ClickFix • Published within a week
Shares tags: Lazarus, ClickFix • Published within a month
Shares tags: Lazarus, ClickFix
Shares tag: Lazarus • Same author: Nurilab • Published within a month
Shares tag: Lazarus • Same author: Nurilab • Published within a month