Is Lazarus/APT38 Targeting Critical Infrastructures ?

2019-11-04 Marcoramilli

https://marcoramilli.com/2019/11/04/is-lazarus-apt38-targeting-critical-infrastructures/amp/

Marco Ramilli analyzed a Windows PE sample publicly linked to the 2019 Kudankulam Nuclear Power Plant incident and assessed it as a targeted information-gathering implant with DTrack/Lazarus similarities. The malware collected local IP, task, routing, interface, software, Firefox `moz_places`, URL, and root-page data, organized results by victim IP, compressed them as `%APPDATA%/Temp/~77FDD3EAMT.tmp`, and attempted to copy them to `10.38.1.35` / `controller5kk` under `Windows\Temp\MpLogs` using hard-coded environment-specific paths and credentials. Ramilli compared the sample to Kaspersky’s DTrack reporting, citing in-memory manipulation and `CCS_` string-handling similarities, while noting DTrack’s historical association with Lazarus/APT38/Hidden Cobra and North Korea. The article is cautious on attribution: it asks whether Lazarus/APT38 was moving toward critical infrastructure or whether the case could be a false flag, with the author personally leaning toward Lazarus expanding into more strategic targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bfb39f486372a509f307cde3361795a… 2019-11-04 2020-03-09
HASH 3cc9d9a12f3b884582e5c4daf7d83c4… 2019-11-04 2020-03-09
HASH c5c1ca4382f397481174914b1931e85… 2019-11-04 2019-11-12
HASH a0664ac662802905329ec6ab3b3ae84… 2019-11-04 2019-11-12
HASH 93a01fbbdd63943c151679d037d32b1… 2019-11-04 2019-11-12
YARA lazarus_dtrack 2019-11-04 2019-11-04
HASH 75171549224b4292974d6ee3cf397db8 2019-11-04 2019-11-04

Related Actors

Related Reports

« Back