Lazarus故技重施,dream job行动再次上演
2022-06-02 • CN-SEC • Lazarus repeats his old tricks and the dream job operation is staged again •
Anheng CERT attributed a renewed Dream Job-style operation to Lazarus after observing Binance developer recruitment lures aimed at job seekers, with the suspected objective of cryptocurrency theft. The delivery chain used password-protected PDF decoys alongside a fake Password.txt LNK file that launched obfuscated PowerShell and mshta to retrieve remote HTA code. Later stages decrypted AES/Gzip-packed PowerShell, attempted UAC bypass, added Windows Defender exclusions, and downloaded Cobalt Strike via gdk.exe and jdk.exe. The activity matters because it shows Lazarus reusing social-engineering patterns against cryptocurrency targets while changing obfuscation and evasion details; reported infrastructure included crypto.blockchaincapital[.]space, mira.itb.ac[.]id, filebin[.]net, and Cobalt Strike callback 174.038.24[.]107:80.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 52b0b06ab4cf6c6b1a13d8eec2705e3b | 2022-06-02 | 2022-06-22 |
| HASH | 89a80c1c39b87754009faf72d6def876 | 2022-06-02 | 2022-06-02 |
| HASH | 9fc45cd7301e1f3f3f98b8d91820aaa1 | 2022-06-02 | 2022-06-02 |
| HASH | c8b2556411ff2ce57c5ae6f44d98ad35 | 2022-06-02 | 2022-06-02 |
| URL | https://crypto.blockchaincapita… | 2022-06-02 | 2022-06-02 |
| URL | https://mira.itb.ac.id/jdk.hta | 2022-06-02 | 2022-06-02 |
| URL | https://crypto.blockchaincapita… | 2022-06-02 | 2022-06-02 |
| URL | https://crypto.blockchaincapita… | 2022-06-02 | 2022-06-02 |
| URL | https://filebin.net/wc3oofuc28p… | 2022-06-02 | 2022-06-02 |
| DOMAIN | crypto.blockchaincapital.space | 2022-06-02 | 2022-06-02 |
| DOMAIN | mira.itb.ac.id | 2022-06-02 | 2022-06-02 |
| HASH | 03933959de20c3d1d40567b7d7fc4f7e | 2022-06-02 | 2022-06-02 |
| HASH | bc2eab8dfc5a0f85eb04eeb1fa19eb91 | 2022-06-02 | 2022-06-02 |
| HASH | 1364f98ccac7821d101950f716f07437 | 2022-06-02 | 2022-06-02 |