Lazarus KillDisks Central American casino

2018-04-03 ESET

https://www.welivesecurity.com/2018/04/03/lazarus-killdisk-central-american-casino/

Thumbnail for Lazarus KillDisks Central American casino

ESET attributes attacks against a Central American online casino and other late-2017 targets to Lazarus based on overlapping toolsets, telemetry, Lazarus-linked malware, and shared static characteristics. The intrusions used Windows service-oriented NukeSped backdoors, a session-hijacking tool, credential theft utilities including a modified Mimikatz, remote access tooling, and destructive Win32/KillDisk.NBO variants deployed across more than 100 machines in the casino network. The KillDisk samples damaged systems by wiping or corrupting data and were closely related to variants seen against Latin American financial organizations. The report highlights how Lazarus combined custom malware, commercial protectors such as VMProtect, public tools, and destructive payloads in a complex multi-stage operation likely intended for cover-up, extortion, or sabotage.

Indicators of Compromise

Type Value First Seen Last Seen
HASH e4b763b4e74de3ef24db6f19108e70c… 2018-04-03 2018-04-03
HASH 5042c16076ae6346af8cf2b40553eee… 2018-04-03 2018-04-03
HASH 18ea298684308e50e3ae6bb66d7321a… 2018-04-03 2018-04-03
HASH d39311c74deb60c736982c1ab74d668… 2018-04-03 2018-04-03
HASH 7c55572e8573d08f3a69fb15b7fef10… 2018-04-03 2018-04-03
HASH e7fdeab60aa4203ea0ff24506b3fc66… 2018-04-03 2018-04-03
HASH 7dfe5f779e46855b32612d168b9cc53… 2018-04-03 2018-04-03
HASH 8826d4edbb00f0a45c23567b16beed2… 2018-04-03 2018-04-03
HASH 429b750d7b1e3b8dfc2264b8143e97e… 2018-04-03 2018-04-03
HASH 325e27077b4a71e6946735d32224ca0… 2018-04-03 2018-04-03

Related Actors

Related Reports

« Back