Lazarus Group continues AppleJeus Operation

2021-10-11 Telsy

https://www.telsy.com/lazarus-group-continues-applejeus-operation/

Thumbnail for Lazarus Group continues AppleJeus Operation

Telsy analyzed Lazarus Group samples tied to the AppleJeus operation, again using a trojanized cryptocurrency trading application as the initial lure. The campaign packaged a malicious version of QtBitcoinTrader in an MSI installer that dropped files under %appdata%/QtBitcoinTrader and scheduled the legitimate CertEnrollCtrl.exe executable. The infection chain used DLL side-loading to load dsparse.dll, which executed shellcode and launched an embedded final backdoor. The backdoor supported multiple commands and communicated over HTTP over TLS with digitalguarder.com, which resolved to 198.54.121.240 and used a Domain Control Validated Sectigo certificate similar to prior AppleJeus infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN digitalguarder.com 2021-10-11 2021-10-11
IPv4 198.54.121.240 2021-10-11 2021-10-11

Related Actors

Related Reports

« Back