Lazarus Group Uses the DLL Side-Loading Technique (2)
2024-01-23 • Ahnlab •
AhnLab identified new Lazarus DLL side-loading variants that use the legitimate Microsoft wmiapsrv.exe module to load malicious wbemcomn.dll and netutils.dll files. The malicious DLLs act as backdoors, and wbemcomn.dll includes a target-verification routine that uses GetSystemFirmwareTable output to decrypt resource strings and load the next file only on specific systems. netutils.dll can load C:\ProgramData\Microsoft Editor\editor.dat without the same verification process, and the excerpt includes PDB information pointing to a loader development path. The behavior is mapped to DLL side-loading under T1574.002 and is presented as part of Lazarus activity against South Korean companies, institutions, think tanks, and related targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 21def97a3c5b95df1e1aeb6486881656 | 2024-01-17 | 2024-01-23 |
| HASH | edca71eda8650a2c591c37c780b6a0c5 | 2024-01-17 | 2024-01-23 |