Lazarus 그룹의 방위산업체 대상 공격 증가

2020-05-08 Ahnlab Increased attacks targeting defense companies by the Lazarus group

https://asec.ahnlab.com/1317

Thumbnail for Lazarus 그룹의 방위산업체 대상 공격 증가

AhnLab observed increased Lazarus activity against defense-related targets using Office Open XML Word documents themed around BAE Systems, Boeing, and U.S.-ROK diplomatic security. The documents reached external template URLs to download macro-enabled .dotm files, then AutoOpen VBA deleted the original lure, displayed a benign document, and created architecture-specific DLLs under Microsoft-looking paths. The DLL execution used exported functions with unique argument strings, abused SQLite-related functionality for information theft, and launched additional rundll32.exe activity. Collected information was sent by POST to C2 infrastructure such as www.astedams[.]it/newsl/offerte-news.asp, with related template URLs hosted on astedams[.]it and od.lk.

Indicators of Compromise

Type Value First Seen Last Seen
URL http://schemas.openxmlformats.o… 2020-03-20 2023-06-06
URL https://www.astedams.it/uploads… 2020-05-08 2020-07-29
URL https://od.lk/d/MzBfMjA1Njc0ODd… 2020-04-30 2020-07-29
URL https://www.astedams.it/uploads… 2020-05-08 2020-05-15

Related Actors

Related Reports

« Back