LAZARUS CAMPAIGNS AND BACKDOORS IN 2022-23

2023-10-04 ESET

https://www.virusbulletin.com/conference/vb2023/abstracts/lazarus-campaigns-and-backdoors-2022-2023/

Attachments

Lazarus-campaigns-and-backdoors-in-2022-2023.pdf (4 MB)

Thumbnail for LAZARUS CAMPAIGNS AND BACKDOORS IN 2022-23

ESET's Virus Bulletin paper details Lazarus campaigns and backdoors observed in 2022 and 2023, tying activity to a North Korea-aligned threat actor through toolset similarities, shared infrastructure, telemetry, and related clustering. The excerpt describes decoy programming challenges against a Spanish aerospace company, Coinbase-themed lures with Windows and macOS payloads targeting individuals in South America, fake Signature Bank and MUFG job offers aimed at banking entities in the United States and Tanzania, an OpenSSL-based backdoor at a South Korean agriculture-related entity, and a Linux lure linked to the 3CX supply-chain case. Lazarus operators are described as relying mostly on social engineering through bogus job offers, crypto news, or investment themes delivered as malicious documents, ZIP files, ISO images, and VHDs, although unknown-vulnerability exploitation is also noted. The malware chain commonly uses droppers, loaders, and downloaders to establish footholds before deploying full-featured RATs and more complex downloaders with encrypted HTTP(S) client-server protocols and multi-step network authentication. The activity matters because the campaigns span Windows, Linux, and macOS and align with espionage, sabotage, financial theft, and cryptocurrency-focused objectives.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
EMAIL [email protected] 2023-10-04 2023-10-04
DOMAIN designlabshop.com 2023-10-04 2023-10-04
DOMAIN freewaremail.com 2023-10-04 2023-10-04
DOMAIN topnewsagent.com 2023-10-04 2023-10-04
DOMAIN webhosttech.org 2023-10-04 2023-10-04
DOMAIN cloudfly.org 2023-10-04 2023-10-04
DOMAIN timecashlive.com 2023-10-04 2023-10-04
DOMAIN designautocad.org 2023-10-04 2023-10-04
DOMAIN dailynewsagent.com 2023-10-04 2023-10-04
DOMAIN shopwebstudio.com 2023-10-04 2023-10-04
DOMAIN cryptyk.ddns.net 2023-10-04 2023-10-04
DOMAIN shopapppro.com 2023-10-04 2023-10-04
DOMAIN techdesignshop.com 2023-10-04 2023-10-04
DOMAIN docs.azurehosting.co 2023-02-16 2023-10-04
IPv4 1.0.0.17 2022-10-24 2023-10-04
DOMAIN concrecapital.com 2022-09-26 2023-10-04
DOMAIN dps.shconstmarket.com 2022-08-17 2023-10-04
DOMAIN markettrendingcenter.com 2022-01-27 2023-10-04
DOMAIN lm-career.com 2022-01-27 2023-10-04

Related Reports

« Back