Lazarus 그룹의 방위산업체 대상 공격 증가
2020-05-08 • Ahnlab • Increased attacks targeting defense companies by the Lazarus group •
AhnLab observed increased Lazarus activity against defense-related targets using Office Open XML Word documents themed around BAE Systems, Boeing, and U.S.-ROK diplomatic security. The documents reached external template URLs to download macro-enabled .dotm files, then AutoOpen VBA deleted the original lure, displayed a benign document, and created architecture-specific DLLs under Microsoft-looking paths. The DLL execution used exported functions with unique argument strings, abused SQLite-related functionality for information theft, and launched additional rundll32.exe activity. Collected information was sent by POST to C2 infrastructure such as www.astedams[.]it/newsl/offerte-news.asp, with related template URLs hosted on astedams[.]it and od.lk.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://schemas.openxmlformats.o… | 2020-03-20 | 2023-06-06 |
| URL | https://www.astedams.it/uploads… | 2020-05-08 | 2020-07-29 |
| URL | https://od.lk/d/MzBfMjA1Njc0ODd… | 2020-04-30 | 2020-07-29 |
| URL | https://www.astedams.it/uploads… | 2020-05-08 | 2020-05-15 |