Is Lazarus/APT38 Targeting Critical Infrastructures ?
2019-11-04 • Marcoramilli •
https://marcoramilli.com/2019/11/04/is-lazarus-apt38-targeting-critical-infrastructures/amp/
Marco Ramilli analyzed a Windows PE sample publicly linked to the 2019 Kudankulam Nuclear Power Plant incident and assessed it as a targeted information-gathering implant with DTrack/Lazarus similarities. The malware collected local IP, task, routing, interface, software, Firefox `moz_places`, URL, and root-page data, organized results by victim IP, compressed them as `%APPDATA%/Temp/~77FDD3EAMT.tmp`, and attempted to copy them to `10.38.1.35` / `controller5kk` under `Windows\Temp\MpLogs` using hard-coded environment-specific paths and credentials. Ramilli compared the sample to Kaspersky’s DTrack reporting, citing in-memory manipulation and `CCS_` string-handling similarities, while noting DTrack’s historical association with Lazarus/APT38/Hidden Cobra and North Korea. The article is cautious on attribution: it asks whether Lazarus/APT38 was moving toward critical infrastructure or whether the case could be a false flag, with the author personally leaning toward Lazarus expanding into more strategic targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | bfb39f486372a509f307cde3361795a… | 2019-11-04 | 2020-03-09 |
| HASH | 3cc9d9a12f3b884582e5c4daf7d83c4… | 2019-11-04 | 2020-03-09 |
| HASH | c5c1ca4382f397481174914b1931e85… | 2019-11-04 | 2019-11-12 |
| HASH | a0664ac662802905329ec6ab3b3ae84… | 2019-11-04 | 2019-11-12 |
| HASH | 93a01fbbdd63943c151679d037d32b1… | 2019-11-04 | 2019-11-12 |
| YARA | lazarus_dtrack | 2019-11-04 | 2019-11-04 |
| HASH | 75171549224b4292974d6ee3cf397db8 | 2019-11-04 | 2019-11-04 |