Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More

2018-01-24 Trend Micro

https://blog.trendmicro.com/trendlabs-security-intelligence/lazarus-campaign-targeting-cryptocurrencies-reveals-remote-controller-tool-evolved-ratankba/

Thumbnail for Lazarus Campaign Targeting Cryptocurrencies Reveals Remote Controller Tool, an Evolved RATANKBA, and More

Trend Micro analyzed a Lazarus RATANKBA variant discovered in June 2017 that moved from a traditional PE executable form to PowerShell while retaining its HTTP-based command protocol. Backend access showed victim data, with roughly 55% of observed RATANKBA PowerShell victims located in India and neighboring countries, including likely employees at web software development companies in India and South Korea rather than large banks. The infection chain used lure documents such as Office files, malicious CHM files, and script downloaders themed around software development or digital currencies, then dropped a backdoor that posted host data and polled a JSP-based C2 for jobs. The controller could queue host-manipulation tasks, execute commands, inject DLLs from URLs, kill the backdoor, and retrieve results, while observed operator artifacts suggested interest in cryptocurrencies including Bitcoin and NEO.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 4722138dda262a2dca5cbf9acd40f15… 2018-01-24 2018-01-24
HASH 10cbb5d0974af08b5d4aa9c753e274a… 2018-01-24 2018-01-24
HASH 6cac0be2120be7b3592fe4e1f7c86f4… 2018-01-24 2018-01-24
HASH 650d7b814922b58b6580041cb0aa9d2… 2018-01-24 2018-01-24
HASH 972b598d709b66b35900dc21c5225e5… 2017-12-19 2018-01-24
HASH 6d4415a2cbedc960c7c7055626c6184… 2017-12-19 2018-01-24
HASH 8ff100ca86cb62117f1290e71d5f9c0… 2017-12-19 2018-01-24
HASH db8163d054a35522d0dec35743cfd2c… 2017-12-19 2018-01-24
HASH d5f9a81df5061c69be9c0ed55fba7d7… 2017-12-19 2018-01-24
HASH 1768f2e9cea5f8c97007c6f822531c1… 2017-12-19 2018-01-24
HASH 772b9b873100375c9696d87724f8efa… 2017-12-19 2018-01-24
HASH 030b4525558f2c411f972d91b144870… 2017-12-19 2018-01-24
HASH d844777dcafcde8622b9472b6cd442c… 2017-12-19 2018-01-24
HASH f7f2dd674532056c0d67ef1fb7c8ae8… 2017-12-19 2018-01-24
HASH 6cb1e9850dd853880bbaf68ea23243b… 2017-12-19 2018-01-24
HASH 9d10911a7bbf26f58b5e39342540761… 2017-12-19 2018-01-24
HASH 01b047e0f3b49f8ab6ebf6795bc72ba… 2017-12-19 2018-01-24

Related Actors

Related Reports

« Back