Lazarus Group's infrastructure reuse leads to discovery of new malware

2023-08-24 Cisco Talos

https://blog.talosintelligence.com/lazarus-collectionrat/

Thumbnail for Lazarus Group's infrastructure reuse leads to discovery of new malware

Talos links Lazarus Group activity exploiting CVE-2022-47966 in ManageEngine ServiceDesk to the deployment of CollectionRAT, alongside QuiteRAT and other tools hosted on reused infrastructure. CollectionRAT is a Windows RAT that fingerprints infected systems, communicates with command-and-control servers, supports arbitrary command execution, file operations, process creation, payload deployment, and self-removal. The report connects CollectionRAT to Jupiter/EarlyRAT through shared code-signing certificate evidence, while noting EarlyRAT has been associated by Kaspersky with Andariel under the Lazarus umbrella. Lazarus also used open-source DeimosC2 as an ELF implant for Linux endpoints and malicious Plink binaries for reverse tunneling, showing a shift toward open-source and dual-use tooling during initial access as well as post-compromise operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH db6a9934570fa98a93a979e7e0e218e… 2023-08-24 2024-12-27
HASH ed8ec7a8dd089019cfd29143f008fa0… 2023-08-24 2024-07-25
HASH 05e9fe8e9e693cb073ba82096c29114… 2023-08-24 2024-07-25
HASH 773760fd71d52457ba53a314f15dddb… 2023-08-24 2024-07-25
HASH e3027062e602c5d1812c039739e2f93… 2023-08-24 2024-07-25
IPv4 108.61.186.55 2023-08-24 2023-09-22
IPv4 146.4.21.94 2022-09-08 2023-09-22
IPv4 109.248.150.13 2022-09-08 2023-09-22

Related Actors

First seen: Jul 2017
Last seen: May 2026

Related Reports

« Back