Lazarus APT组织使用西方某航空巨头招聘等信息针对特定国家的定向攻击事件分析
2020-04-30 • Qianxin • Analysis of targeted attacks against specific countries by the Lazarus APT organization using recruitment information from a Western aviation giant •
https://ti.qianxin.com/blog/articles/analysis-of-lazarus-apt-oriented-attack-event/
QiAnXin reported a Lazarus-attributed targeted campaign using diplomatic-relations themes and Western aerospace recruitment lures, including Boeing-themed documents, to attack specific countries. The samples used remote template injection to fetch macro-enabled DOTM documents, helping evade antivirus detection before macros decoded embedded data and dropped 32-bit or 64-bit DLL payloads. The DLLs deleted the original document, established persistence with a startup-folder LNK, collected host and user information, and contacted C2 for follow-on execution, though the final malware was not recovered. QiAnXin linked the activity to Lazarus through similarities with previously reported Telsy activity, matching macro flow, DLL logic, and backdoor behavior.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f4b55da7870e9ecd5f3f565f40490996 | 2020-04-30 | 2023-04-12 |
| HASH | 2b02465b65024336a9e15d7f34c1f5d9 | 2020-04-30 | 2023-04-12 |
| HASH | 4c239a926676087e31d82e79e838ced1 | 2020-04-30 | 2023-04-12 |
| HASH | 183ad96b931733ad37bb627a958837db | 2020-04-30 | 2023-04-12 |
| HASH | 65df11dea0c1d0f0304b376787e65ccb | 2020-04-30 | 2023-04-12 |
| HASH | 2efbe6901fc3f479bc32aaf13ce8cf12 | 2020-04-30 | 2023-04-12 |
| HASH | f6d6f3580160cd29b285edf7d0c647ce | 2020-04-30 | 2023-04-12 |
| HASH | 11fdc0be9d85b4ff1faf5ca33cc272ed | 2020-04-30 | 2023-04-12 |
| URL | https://od.lk/d/MzBfMjA1Njc0ODd… | 2020-04-30 | 2020-07-29 |
| URL | https://www.sanlorenzoyacht.com… | 2020-04-30 | 2020-07-29 |
| URL | https://www.elite4print.com/adm… | 2020-04-30 | 2020-04-30 |