From BYOVD to a 0-day: Unveiling Advanced Exploits in Cyber Recruiting Scams

2024-04-18 Avast

https://decoded.avast.io/luiginocamastra/from-byovd-to-a-0-day-unveiling-advanced-exploits-in-cyber-recruiting-scams/

Thumbnail for From BYOVD to a 0-day: Unveiling Advanced Exploits in Cyber Recruiting Scams

Avast found a Lazarus campaign that targeted selected individuals in Asia through fabricated job offers, using rapport-building before delivering a malicious ISO disguised as a VNC tool. The ISO executed a legitimate Windows choice.exe binary to sideload a malicious version.dll, which then launched or injected an obfuscated aws.cfg payload and attempted to download shellcode from a compromised website. The infection chain connected RollFling, RollSling, RollMid, and KaolinRAT, with stages designed to run in memory, use victim-specific SMBIOS data for decryption, and support RAT functions such as DLL loading and timestamp manipulation. Lazarus also exploited CVE-2024-21338 in the Windows appid.sys driver to blind security products through the FudModule 2.0 rootkit, showing a highly resourced, targeted operation against technically relevant victims.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b8a4c1792ce2ec15611932437a4a1a7… 2024-04-18 2024-04-18
HASH 9a4bc647c09775ed633c134643d18a0… 2024-04-18 2024-04-18
HASH 01ca7070bbe4bfa6254886f8599d6ce… 2024-04-18 2024-04-18
HASH e68ff1087c45a1711c3037dad427733… 2024-04-18 2024-04-18
HASH f47f78b5eef672e8e1bd0f26fb4aa69… 2024-04-18 2024-04-18
HASH a3fe80540363ee2f1216ec3d01209d7… 2024-04-18 2024-04-18
HASH a75399f9492a8d2683d4406fa3e1320… 2024-04-18 2024-04-18
HASH 7248d66dea78a73b9b80b528d7e9f53… 2024-04-18 2024-04-18
URL https://www.henraux.com/ 2024-04-18 2024-04-18
URL https://www.henraux.com/sitemap… 2024-04-18 2024-04-18

Related Reports

« Back