LAZARUS’ FALSE FLAG MALWARE

2017-02-20 Bae Systems

http://baesystemsai.blogspot.kr/2017/02/lazarus-false-flag-malware.html

Thumbnail for LAZARUS’ FALSE FLAG MALWARE

BAE Systems analyzed malware and watering-hole infrastructure tied to a wave of bank attacks that earlier reporting had linked to the Lazarus threat actor. The examined samples included an encrypted backdoor loaded by a DLL, decrypted with XOR and RC4 routines, then injected into a process and controlled through a custom binary protocol supporting file transfer and remote download commands. The attackers used compromised websites to redirect selected visitors to a profiling script that checked IP allowlists, browser details, operating system version, and plugins before serving Adobe Flash or Microsoft Silverlight exploits. Russian-language command strings in the bot appeared inconsistent with native Russian usage, leading the researchers to assess them as a likely decoy intended to spoof the malware’s origin. The report matters because it connects targeted financial-sector watering holes, exploit-kit filtering, Lazarus-linked loader behavior, and false-flag language artifacts into a defensible detection picture.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e29fe3c181ac9ddbb242688b151f3310 2017-02-20 2017-04-03
HASH 9cc6854bc5e217104734043c89dc4ff8 2017-02-20 2017-02-20
HASH 9914075cc687bdc352ee136ac6579707 2017-02-20 2017-02-20
HASH 889e320cf66520485e1a0475107d7419 2017-02-20 2017-02-20
HASH 8e32fccd70cec634d13795bcb1da85ff 2017-02-20 2017-02-20
HASH 9216b29114fb6713ef228370cbfe4045 2017-02-20 2017-02-20
HASH 6dffcfa68433f886b2e88fd984b4995a 2017-02-12 2017-02-20

Related Actors

Related Reports

« Back