Lazarus APT组织使用西方某航空巨头招聘等信息针对特定国家的定向攻击事件分析

2020-04-30 Qianxin Analysis of targeted attacks against specific countries by the Lazarus APT organization using recruitment information from a Western aviation giant

https://ti.qianxin.com/blog/articles/analysis-of-lazarus-apt-oriented-attack-event/

Thumbnail for Lazarus APT组织使用西方某航空巨头招聘等信息针对特定国家的定向攻击事件分析

QiAnXin reported a Lazarus-attributed targeted campaign using diplomatic-relations themes and Western aerospace recruitment lures, including Boeing-themed documents, to attack specific countries. The samples used remote template injection to fetch macro-enabled DOTM documents, helping evade antivirus detection before macros decoded embedded data and dropped 32-bit or 64-bit DLL payloads. The DLLs deleted the original document, established persistence with a startup-folder LNK, collected host and user information, and contacted C2 for follow-on execution, though the final malware was not recovered. QiAnXin linked the activity to Lazarus through similarities with previously reported Telsy activity, matching macro flow, DLL logic, and backdoor behavior.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f4b55da7870e9ecd5f3f565f40490996 2020-04-30 2023-04-12
HASH 2b02465b65024336a9e15d7f34c1f5d9 2020-04-30 2023-04-12
HASH 4c239a926676087e31d82e79e838ced1 2020-04-30 2023-04-12
HASH 183ad96b931733ad37bb627a958837db 2020-04-30 2023-04-12
HASH 65df11dea0c1d0f0304b376787e65ccb 2020-04-30 2023-04-12
HASH 2efbe6901fc3f479bc32aaf13ce8cf12 2020-04-30 2023-04-12
HASH f6d6f3580160cd29b285edf7d0c647ce 2020-04-30 2023-04-12
HASH 11fdc0be9d85b4ff1faf5ca33cc272ed 2020-04-30 2023-04-12
URL https://od.lk/d/MzBfMjA1Njc0ODd… 2020-04-30 2020-07-29
URL https://www.sanlorenzoyacht.com… 2020-04-30 2020-07-29
URL https://www.elite4print.com/adm… 2020-04-30 2020-04-30

Related Actors

Related Reports

« Back