LAZARUS’ FALSE FLAG MALWARE
2017-02-20 • Bae Systems •
http://baesystemsai.blogspot.kr/2017/02/lazarus-false-flag-malware.html
BAE Systems analyzed malware and watering-hole infrastructure tied to a wave of bank attacks that earlier reporting had linked to the Lazarus threat actor. The examined samples included an encrypted backdoor loaded by a DLL, decrypted with XOR and RC4 routines, then injected into a process and controlled through a custom binary protocol supporting file transfer and remote download commands. The attackers used compromised websites to redirect selected visitors to a profiling script that checked IP allowlists, browser details, operating system version, and plugins before serving Adobe Flash or Microsoft Silverlight exploits. Russian-language command strings in the bot appeared inconsistent with native Russian usage, leading the researchers to assess them as a likely decoy intended to spoof the malware’s origin. The report matters because it connects targeted financial-sector watering holes, exploit-kit filtering, Lazarus-linked loader behavior, and false-flag language artifacts into a defensible detection picture.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e29fe3c181ac9ddbb242688b151f3310 | 2017-02-20 | 2017-04-03 |
| HASH | 9cc6854bc5e217104734043c89dc4ff8 | 2017-02-20 | 2017-02-20 |
| HASH | 9914075cc687bdc352ee136ac6579707 | 2017-02-20 | 2017-02-20 |
| HASH | 889e320cf66520485e1a0475107d7419 | 2017-02-20 | 2017-02-20 |
| HASH | 8e32fccd70cec634d13795bcb1da85ff | 2017-02-20 | 2017-02-20 |
| HASH | 9216b29114fb6713ef228370cbfe4045 | 2017-02-20 | 2017-02-20 |
| HASH | 6dffcfa68433f886b2e88fd984b4995a | 2017-02-12 | 2017-02-20 |