Lazarus故技重施,dream job行动再次上演

2022-06-02 CN-SEC Lazarus repeats his old tricks and the dream job operation is staged again

https://cn-sec.com/archives/1080507.html

Thumbnail for Lazarus故技重施,dream job行动再次上演

Anheng CERT attributed a renewed Dream Job-style operation to Lazarus after observing Binance developer recruitment lures aimed at job seekers, with the suspected objective of cryptocurrency theft. The delivery chain used password-protected PDF decoys alongside a fake Password.txt LNK file that launched obfuscated PowerShell and mshta to retrieve remote HTA code. Later stages decrypted AES/Gzip-packed PowerShell, attempted UAC bypass, added Windows Defender exclusions, and downloaded Cobalt Strike via gdk.exe and jdk.exe. The activity matters because it shows Lazarus reusing social-engineering patterns against cryptocurrency targets while changing obfuscation and evasion details; reported infrastructure included crypto.blockchaincapital[.]space, mira.itb.ac[.]id, filebin[.]net, and Cobalt Strike callback 174.038.24[.]107:80.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 52b0b06ab4cf6c6b1a13d8eec2705e3b 2022-06-02 2022-06-22
HASH 89a80c1c39b87754009faf72d6def876 2022-06-02 2022-06-02
HASH 9fc45cd7301e1f3f3f98b8d91820aaa1 2022-06-02 2022-06-02
HASH c8b2556411ff2ce57c5ae6f44d98ad35 2022-06-02 2022-06-02
URL https://crypto.blockchaincapita… 2022-06-02 2022-06-02
URL https://mira.itb.ac.id/jdk.hta 2022-06-02 2022-06-02
URL https://crypto.blockchaincapita… 2022-06-02 2022-06-02
URL https://crypto.blockchaincapita… 2022-06-02 2022-06-02
URL https://filebin.net/wc3oofuc28p… 2022-06-02 2022-06-02
DOMAIN crypto.blockchaincapital.space 2022-06-02 2022-06-02
DOMAIN mira.itb.ac.id 2022-06-02 2022-06-02
HASH 03933959de20c3d1d40567b7d7fc4f7e 2022-06-02 2022-06-02
HASH bc2eab8dfc5a0f85eb04eeb1fa19eb91 2022-06-02 2022-06-02
HASH 1364f98ccac7821d101950f716f07437 2022-06-02 2022-06-02

Related Reports

« Back