Lazarus Exploits a Zoho ManageEngine Vulnerability to Distribute QuiteRAT and CollectionRAT

2023-09-22 Hawkeye

https://www.hawk-eye.io/2023/09/lazarus-exploits-a-zoho-manageengine-vulnerability-to-distribute-quiterat-and-collectionrat/

Thumbnail for Lazarus Exploits a Zoho ManageEngine Vulnerability to Distribute QuiteRAT and CollectionRAT

Lazarus exploited CVE-2022-47966, a pre-authentication RCE flaw in Zoho ManageEngine products, to compromise vulnerable ServiceDesk Plus instances and deploy QuiteRAT against UK internet service providers as well as internet backbone suppliers and healthcare organizations in the US and UK. QuiteRAT is presented as a smaller successor to MagicRAT, retaining remote access capabilities such as system information collection, process execution, file management, reverse shells, payload fetching, and self-deletion while relying on C2-provided persistence. The infection chain begins with exploitation of the exposed ManageEngine server, after which the Java runtime downloads and runs the QuiteRAT binary, which beacons basic system data to C2 infrastructure and waits for command codes or Windows commands executed through child cmd.exe processes. Reused Lazarus infrastructure also led researchers to CollectionRAT, a Windows MFC-based RAT that fingerprints victims, supports reverse shell activity, file read/write, process spawning, additional payload execution, and self-deletion. The excerpt includes hashes, IPs, and URLs tied to the activity, and notes supporting tradecraft such as DeimosC2, Plink, and Mimikatz.

Indicators of Compromise

Type Value First Seen Last Seen
HASH db6a9934570fa98a93a979e7e0e218e… 2023-08-24 2024-12-27
HASH ed8ec7a8dd089019cfd29143f008fa0… 2023-08-24 2024-07-25
HASH 05e9fe8e9e693cb073ba82096c29114… 2023-08-24 2024-07-25
HASH 773760fd71d52457ba53a314f15dddb… 2023-08-24 2024-07-25
HASH e3027062e602c5d1812c039739e2f93… 2023-08-24 2024-07-25
IPv4 108.61.186.55 2023-08-24 2023-09-22
IPv4 146.4.21.94 2022-09-08 2023-09-22
IPv4 109.248.150.13 2022-09-08 2023-09-22

Related Reports

« Back