Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT

2023-08-24 Cisco Talos

https://blog.talosintelligence.com/lazarus-quiterat/

Thumbnail for Lazarus Group exploits ManageEngine vulnerability to deploy QuiteRAT

Cisco Talos observed Lazarus Group compromising internet backbone infrastructure in Europe and targeting healthcare entities in the United States by exploiting CVE-2022-47966 in ManageEngine ServiceDesk. The attackers used the vulnerability shortly after public proof-of-concept code appeared to download and execute QuiteRAT from Lazarus-linked infrastructure, including IP address 146.4.21.94. QuiteRAT is a compact Qt-based remote access trojan derived from or closely related to MagicRAT, with capabilities for host fingerprinting, C2 communication, arbitrary command execution through cmd.exe, sleep control, and secondary C2 retrieval. Persistence was not built into the implant and was instead established through a service-creation command issued by the operators, while its Qt framework use complicates human analysis and weakens some heuristic detection approaches.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ed8ec7a8dd089019cfd29143f008fa0… 2023-08-24 2024-07-25
IPv4 146.4.21.94 2022-09-08 2023-09-22

Related Reports

« Back