LAZARUS CAMPAIGNS AND BACKDOORS IN 2022-23
2023-10-04 • ESET •
https://www.virusbulletin.com/conference/vb2023/abstracts/lazarus-campaigns-and-backdoors-2022-2023/
Attachments
ESET's Virus Bulletin paper details Lazarus campaigns and backdoors observed in 2022 and 2023, tying activity to a North Korea-aligned threat actor through toolset similarities, shared infrastructure, telemetry, and related clustering. The excerpt describes decoy programming challenges against a Spanish aerospace company, Coinbase-themed lures with Windows and macOS payloads targeting individuals in South America, fake Signature Bank and MUFG job offers aimed at banking entities in the United States and Tanzania, an OpenSSL-based backdoor at a South Korean agriculture-related entity, and a Linux lure linked to the 3CX supply-chain case. Lazarus operators are described as relying mostly on social engineering through bogus job offers, crypto news, or investment themes delivered as malicious documents, ZIP files, ISO images, and VHDs, although unknown-vulnerability exploitation is also noted. The malware chain commonly uses droppers, loaders, and downloaders to establish footholds before deploying full-featured RATs and more complex downloaders with encrypted HTTP(S) client-server protocols and multi-step network authentication. The activity matters because the campaigns span Windows, Linux, and macOS and align with espionage, sabotage, financial theft, and cryptocurrency-focused objectives.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| [email protected] | 2023-10-04 | 2023-10-04 | |
| DOMAIN | designlabshop.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | freewaremail.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | topnewsagent.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | webhosttech.org | 2023-10-04 | 2023-10-04 |
| DOMAIN | cloudfly.org | 2023-10-04 | 2023-10-04 |
| DOMAIN | timecashlive.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | designautocad.org | 2023-10-04 | 2023-10-04 |
| DOMAIN | dailynewsagent.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | shopwebstudio.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | cryptyk.ddns.net | 2023-10-04 | 2023-10-04 |
| DOMAIN | shopapppro.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | techdesignshop.com | 2023-10-04 | 2023-10-04 |
| DOMAIN | docs.azurehosting.co | 2023-02-16 | 2023-10-04 |
| IPv4 | 1.0.0.17 | 2022-10-24 | 2023-10-04 |
| DOMAIN | concrecapital.com | 2022-09-26 | 2023-10-04 |
| DOMAIN | dps.shconstmarket.com | 2022-08-17 | 2023-10-04 |
| DOMAIN | markettrendingcenter.com | 2022-01-27 | 2023-10-04 |
| DOMAIN | lm-career.com | 2022-01-27 | 2023-10-04 |