Lazarus组织针对加密货币行业的社工攻击
2021-07-20 • Qihoo360 • Lazarus Group's Social Engineering Attack Targets Cryptocurrency Industry •
Sangfor attributes a social-engineering operation against cryptocurrency-sector targets to Lazarus based on victimology and technical overlap with earlier Lazarus campaigns against security researchers. Operators allegedly contacted targets over instant messaging and delivered a modified open-source Secure PDF Viewer executable together with an encrypted lure PDF named Android Hardware Wallet.pdf, inducing victims to use the executable to open the document. The viewer checked a marker in the PDF, XOR-decrypted embedded data, dropped MSCache.cpl/CAST.dll, launched it with rundll32, and executed an in-memory downloader that attempted to retrieve a fourth-stage payload from C2. The report notes a Lazarus-like execution format, an image/upload/upload.asp C2 path, and indicators including smartaudpor.com plus MD5 hashes for the delivered components.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 93d04c28e2f1448a273a8e554260bd9d | 2021-07-20 | 2021-07-20 |
| HASH | 1a00ef6c4cc9ae09f3f7d59cd726add1 | 2021-07-20 | 2021-07-20 |
| HASH | 819edb8646bf2f877ab636a8b27caafd | 2021-07-20 | 2021-07-20 |
| URL | https://www.smartaudpor.com/ima… | 2021-07-20 | 2021-07-20 |