Lazarus Exploits a Zoho ManageEngine Vulnerability to Distribute QuiteRAT and CollectionRAT
2023-09-22 • Hawkeye •
Lazarus exploited CVE-2022-47966, a pre-authentication RCE flaw in Zoho ManageEngine products, to compromise vulnerable ServiceDesk Plus instances and deploy QuiteRAT against UK internet service providers as well as internet backbone suppliers and healthcare organizations in the US and UK. QuiteRAT is presented as a smaller successor to MagicRAT, retaining remote access capabilities such as system information collection, process execution, file management, reverse shells, payload fetching, and self-deletion while relying on C2-provided persistence. The infection chain begins with exploitation of the exposed ManageEngine server, after which the Java runtime downloads and runs the QuiteRAT binary, which beacons basic system data to C2 infrastructure and waits for command codes or Windows commands executed through child cmd.exe processes. Reused Lazarus infrastructure also led researchers to CollectionRAT, a Windows MFC-based RAT that fingerprints victims, supports reverse shell activity, file read/write, process spawning, additional payload execution, and self-deletion. The excerpt includes hashes, IPs, and URLs tied to the activity, and notes supporting tradecraft such as DeimosC2, Plink, and Mimikatz.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | db6a9934570fa98a93a979e7e0e218e… | 2023-08-24 | 2024-12-27 |
| HASH | ed8ec7a8dd089019cfd29143f008fa0… | 2023-08-24 | 2024-07-25 |
| HASH | 05e9fe8e9e693cb073ba82096c29114… | 2023-08-24 | 2024-07-25 |
| HASH | 773760fd71d52457ba53a314f15dddb… | 2023-08-24 | 2024-07-25 |
| HASH | e3027062e602c5d1812c039739e2f93… | 2023-08-24 | 2024-07-25 |
| IPv4 | 108.61.186.55 | 2023-08-24 | 2023-09-22 |
| IPv4 | 146.4.21.94 | 2022-09-08 | 2023-09-22 |
| IPv4 | 109.248.150.13 | 2022-09-08 | 2023-09-22 |