Hunting for Unsigned DLLs to Find APTs

2022-09-26 Paloalto Networks

https://unit42.paloaltonetworks.com/unsigned-dlls/

Thumbnail for Hunting for Unsigned DLLs to Find APTs

Unit 42 used unsigned-DLL hunting to surface APT activity, including a North Korean cluster it tracks as Selective Pisces, also known as Lazarus Group, ZINC, or APT-C-26. In the DPRK-linked case, MagicLine4NX.exe from DreamSecurity dropped unsigned modules into ProgramData and enabled DLL side-loading through a copied Windows wsmprovhost.exe process that loaded a malicious mi.dll. The chain then placed ualapi.dll under C:\Windows\System32 to gain persistence through spoolsv.exe loading behavior, illustrating how the actor abused legitimate Korean third-party software and Windows DLL search behavior. The report matters for detection because it contrasts common rundll32/regsvr32 DLL loading with APT-style DLL side-loading and gives defenders concrete hunting logic for unsigned DLL execution in user-writable paths.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 32449fd81cc4f85213ed791478ec941… 2022-09-26 2022-09-26
HASH cf9ccba037f807c5be523528ed25cee… 2022-09-26 2022-09-26
HASH 9973045c0489a0382db84aef6356414… 2022-09-26 2022-09-26
HASH e8f55d0f327fd1d5f26428b890ef7fe… 2022-09-26 2022-09-26
HASH 06f11ea2d7d566e33ed414993da00ac… 2022-09-26 2022-09-26
HASH 9fad2f59737721c26fc2a125e18dd67… 2022-09-26 2022-09-26
HASH 6491c646397025bf02709f1bd3025f1… 2022-09-26 2022-09-26
HASH f9e4627733e034cfc1c589afd2f6558… 2022-09-26 2022-09-26
HASH 5bb4950a05a46f7d377a3a848348422… 2022-09-26 2022-09-26
HASH 3131985fa7394fa9dbd9c9b26e15ac4… 2022-09-26 2022-09-26
HASH 5a8b1f003ae566a8e443623a18c1f10… 2022-09-26 2022-09-26
HASH 18cc18d02742da3fa88fc8c45fe915d… 2022-09-26 2022-09-26
HASH d9b1ad70c0a043d034f8eecd55a8290… 2022-09-26 2022-09-26
HASH 202dab603585f600dbd884cb5bd5bf0… 2022-09-26 2022-09-26
HASH 352fb4985fdd150d251ff9e20ca1402… 2022-09-26 2022-09-26
HASH 5be717dc9eda4df099e090f2a59c253… 2022-09-26 2022-09-26
HASH 779a6772d4d35e1b0018a03b75cc6f9… 2022-09-26 2022-09-26
HASH 79b7964bde948b70a7c3869d34fe5d5… 2022-04-14 2022-09-26
HASH 7aa62af5a55022fd89b3f0c025ea508… 2022-04-14 2022-09-26

Related Actors

Related Reports

« Back