Cyber Threats 2021: A Year in Retrospect
2022-04-29 • PWC •
Attachments
PwC highlighted North Korea-based Black Artemis, also known as Lazarus Group, as continuing to use job-specification lure documents against targets in high-profile defense and engineering companies. The activity often followed social engineering in which the actor posed as a recruiter on platforms such as LinkedIn to build rapport before delivering malicious attachments. PwC also noted Black Banshee, also known as Kimsuky or Velvet Chollima, using lightly obfuscated PowerShell commands hidden in malicious macros to download payloads from a remote staging server and execute them. These examples show DPRK-linked actors continuing to rely on spearphishing, malicious documents, macros, and PowerShell execution within broader 2021 threat activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| YARA | Microsoft_Signed_DLL_With_High_… | 2022-04-29 | 2022-04-29 |
| YARA | Red_Lich_Encoded_PlugX | 2022-04-29 | 2022-04-29 |
| HASH | 56e9b0c2b87d45ee0c109fb71d43662… | 2022-04-29 | 2022-04-29 |
| HASH | d69d200513a173aff3a4b2474ccc118… | 2022-04-29 | 2022-04-29 |
| HASH | 69adaf19cc19594e0193da88597b6af… | 2022-04-29 | 2022-04-29 |
| HASH | 8ef94327cab01af04a83df86a662f3a… | 2022-04-29 | 2022-04-29 |
| HASH | 94c7965e0fba7deb71ca0ff7901b1a1… | 2022-04-29 | 2022-04-29 |
| HASH | 5eaaf8ac2d358c2d7065884b7994638… | 2022-04-29 | 2022-04-29 |
| HASH | 697be6add418ca9e1ebcef6cc6fdbb6… | 2022-04-29 | 2022-04-29 |
| URL | https://www.cynet.com/attack-te… | 2022-04-29 | 2022-04-29 |
| URL | http://schemas.openxmlformats.o… | 2022-04-29 | 2022-04-29 |
| URL | https://www.technologyreview.co… | 2022-04-29 | 2022-04-29 |
| DOMAIN | mail-mailbox-microsoft.com | 2022-04-29 | 2022-04-29 |
| DOMAIN | micr0soft.com | 2022-04-29 | 2022-04-29 |
| DOMAIN | attack.mitre | 2022-04-29 | 2022-04-29 |