Lazarus Group's infrastructure reuse leads to discovery of new malware
2023-08-24 • Cisco Talos •
Talos links Lazarus Group activity exploiting CVE-2022-47966 in ManageEngine ServiceDesk to the deployment of CollectionRAT, alongside QuiteRAT and other tools hosted on reused infrastructure. CollectionRAT is a Windows RAT that fingerprints infected systems, communicates with command-and-control servers, supports arbitrary command execution, file operations, process creation, payload deployment, and self-removal. The report connects CollectionRAT to Jupiter/EarlyRAT through shared code-signing certificate evidence, while noting EarlyRAT has been associated by Kaspersky with Andariel under the Lazarus umbrella. Lazarus also used open-source DeimosC2 as an ELF implant for Linux endpoints and malicious Plink binaries for reverse tunneling, showing a shift toward open-source and dual-use tooling during initial access as well as post-compromise operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | db6a9934570fa98a93a979e7e0e218e… | 2023-08-24 | 2024-12-27 |
| HASH | ed8ec7a8dd089019cfd29143f008fa0… | 2023-08-24 | 2024-07-25 |
| HASH | 05e9fe8e9e693cb073ba82096c29114… | 2023-08-24 | 2024-07-25 |
| HASH | 773760fd71d52457ba53a314f15dddb… | 2023-08-24 | 2024-07-25 |
| HASH | e3027062e602c5d1812c039739e2f93… | 2023-08-24 | 2024-07-25 |
| IPv4 | 108.61.186.55 | 2023-08-24 | 2023-09-22 |
| IPv4 | 146.4.21.94 | 2022-09-08 | 2023-09-22 |
| IPv4 | 109.248.150.13 | 2022-09-08 | 2023-09-22 |