Lazarus KillDisks Central American casino
2018-04-03 • ESET •
https://www.welivesecurity.com/2018/04/03/lazarus-killdisk-central-american-casino/
ESET attributes attacks against a Central American online casino and other late-2017 targets to Lazarus based on overlapping toolsets, telemetry, Lazarus-linked malware, and shared static characteristics. The intrusions used Windows service-oriented NukeSped backdoors, a session-hijacking tool, credential theft utilities including a modified Mimikatz, remote access tooling, and destructive Win32/KillDisk.NBO variants deployed across more than 100 machines in the casino network. The KillDisk samples damaged systems by wiping or corrupting data and were closely related to variants seen against Latin American financial organizations. The report highlights how Lazarus combined custom malware, commercial protectors such as VMProtect, public tools, and destructive payloads in a complex multi-stage operation likely intended for cover-up, extortion, or sabotage.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | e4b763b4e74de3ef24db6f19108e70c… | 2018-04-03 | 2018-04-03 |
| HASH | 5042c16076ae6346af8cf2b40553eee… | 2018-04-03 | 2018-04-03 |
| HASH | 18ea298684308e50e3ae6bb66d7321a… | 2018-04-03 | 2018-04-03 |
| HASH | d39311c74deb60c736982c1ab74d668… | 2018-04-03 | 2018-04-03 |
| HASH | 7c55572e8573d08f3a69fb15b7fef10… | 2018-04-03 | 2018-04-03 |
| HASH | e7fdeab60aa4203ea0ff24506b3fc66… | 2018-04-03 | 2018-04-03 |
| HASH | 7dfe5f779e46855b32612d168b9cc53… | 2018-04-03 | 2018-04-03 |
| HASH | 8826d4edbb00f0a45c23567b16beed2… | 2018-04-03 | 2018-04-03 |
| HASH | 429b750d7b1e3b8dfc2264b8143e97e… | 2018-04-03 | 2018-04-03 |
| HASH | 325e27077b4a71e6946735d32224ca0… | 2018-04-03 | 2018-04-03 |