From BYOVD to a 0-day: Unveiling Advanced Exploits in Cyber Recruiting Scams
2024-04-18 • Avast •
Avast found a Lazarus campaign that targeted selected individuals in Asia through fabricated job offers, using rapport-building before delivering a malicious ISO disguised as a VNC tool. The ISO executed a legitimate Windows choice.exe binary to sideload a malicious version.dll, which then launched or injected an obfuscated aws.cfg payload and attempted to download shellcode from a compromised website. The infection chain connected RollFling, RollSling, RollMid, and KaolinRAT, with stages designed to run in memory, use victim-specific SMBIOS data for decryption, and support RAT functions such as DLL loading and timestamp manipulation. Lazarus also exploited CVE-2024-21338 in the Windows appid.sys driver to blind security products through the FudModule 2.0 rootkit, showing a highly resourced, targeted operation against technically relevant victims.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b8a4c1792ce2ec15611932437a4a1a7… | 2024-04-18 | 2024-04-18 |
| HASH | 9a4bc647c09775ed633c134643d18a0… | 2024-04-18 | 2024-04-18 |
| HASH | 01ca7070bbe4bfa6254886f8599d6ce… | 2024-04-18 | 2024-04-18 |
| HASH | e68ff1087c45a1711c3037dad427733… | 2024-04-18 | 2024-04-18 |
| HASH | f47f78b5eef672e8e1bd0f26fb4aa69… | 2024-04-18 | 2024-04-18 |
| HASH | a3fe80540363ee2f1216ec3d01209d7… | 2024-04-18 | 2024-04-18 |
| HASH | a75399f9492a8d2683d4406fa3e1320… | 2024-04-18 | 2024-04-18 |
| HASH | 7248d66dea78a73b9b80b528d7e9f53… | 2024-04-18 | 2024-04-18 |
| URL | https://www.henraux.com/ | 2024-04-18 | 2024-04-18 |
| URL | https://www.henraux.com/sitemap… | 2024-04-18 | 2024-04-18 |