Lazarus组织对加密货币行业持续发起攻击 - 安恒威胁情报中心

2020-11-24 安恒信息 The Lazarus group continues to launch attacks on the cryptocurrency industry - Anheng Threat Intelligence Center

https://starmap.dbappsecurity.com.cn/blog/articles/2020/11/24/lazarus-group-continues-to-launch-attacks-on-the-cryptocurrency-industry/

Thumbnail for Lazarus组织对加密货币行业持续发起攻击 - 安恒威胁情报中心

DBAPPSecurity attributed a set of cryptocurrency-themed LNK attacks to Lazarus activity against exchanges, industry staff, and digital-currency users. One Japanese-language lure masqueraded as business guidance and executed `mshta` through a Bitly short link, fetched decoy content from Google Drive, checked for security processes such as Kingsoft and NPAV, and ran a base64-encoded script that beaconed to C2 every 15 seconds for follow-on payloads. The report links related samples through shared usernames, document metadata, Korean language settings, and similar TTPs from earlier Lazarus cryptocurrency campaigns. It also identifies associated infrastructure such as `up.myemail[.]works`, `filehost[.]network`, and Google Drive decoy links.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 84.201.189.216 2020-11-24 2021-02-01
HASH a164164ef82fa17605c49c36c67a6244 2020-11-24 2021-01-28
HASH 14a00f517012279af53118a491253e5c 2020-11-24 2021-01-28
HASH 12aa32ee18926c597f3c0387f0775577 2020-11-24 2021-01-28
HASH 224d2398437e665f3202d4118e4748e2 2020-11-24 2021-01-28
IPv4 89.134.49.3 2020-11-24 2021-01-28
HASH fb1c6e467956ec29c098bb18474a2ef6 2020-11-24 2020-11-24
HASH c1f725abaf4e82ff1a4042f84d226643 2020-11-24 2020-11-24
HASH 9d555c1093ff84ac3d442b1a0617f7ef 2020-11-24 2020-11-24
HASH 0efc5c754b6739be19d5478fdffde7f5 2020-11-24 2020-11-24
HASH 4da5e7d083af1ba3872c205ff27de8cc 2020-11-24 2020-11-24
HASH f316f341f923c1598dbbb6967c1c66e2 2020-11-24 2020-11-24
HASH a2bfa52ac21ab618fb7f8af1261b6428 2020-11-24 2020-11-24
HASH a2117f2058043ef757af6e5d45afa491 2020-11-24 2020-11-24
URL http://up.myemail.works/+Eu8cue… 2020-11-24 2020-11-24
URL http://up.myemail.works/GezS0o/… 2020-11-24 2020-11-24
DOMAIN sharesvr.net 2020-11-24 2020-11-24
DOMAIN cloud-sheet.net 2020-11-24 2020-11-24
DOMAIN msftoffice.com 2020-11-24 2020-11-24
DOMAIN anicloud.ru 2020-11-24 2020-11-24
DOMAIN up.myemail.works 2020-11-24 2020-11-24

Related Actors

Related Reports

« Back