Lazarus on the hunt for big game
2020-07-28 • Kaspersky •
https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
Kaspersky linked VHD ransomware operations to Lazarus after incident-response evidence showed a MATA framework backdoor in the same victim environment and no sign of another actor during the intrusion. One European incident used a victim-specific spreading utility with administrative credentials and IP addresses to brute-force SMB, copy the ransomware, and execute it through WMI. A later case likely began with opportunistic VPN exploitation, privilege escalation, a backdoor deployment, Active Directory takeover, and network-wide VHD staging through a Python downloader within about 10 hours. The ransomware used AES-256 in ECB mode and RSA-2048, while the report lists MATA command-and-control infrastructure and VHD hashes, making the activity notable as a Lazarus-run targeted ransomware operation rather than a typical outsourced cybercrime ecosystem case.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 104.232.71.7 | 2020-07-22 | 2021-03-23 |
| IPv4 | 172.93.184.62 | 2020-07-22 | 2021-03-23 |
| IPv4 | 23.227.199.69 | 2020-07-22 | 2021-03-23 |
| HASH | ccc6026acf7eadada9adaccab70ca4d6 | 2020-07-28 | 2020-07-28 |
| HASH | dd00a8610bb84b54e99ae8099db1fc20 | 2020-07-28 | 2020-07-28 |
| HASH | d0806c9d8bcea0bd47d80fa004744d7d | 2020-07-28 | 2020-07-28 |
| HASH | efd4a87e7c5dcbb64b7313a13b4b1012 | 2020-07-28 | 2020-07-28 |
| HASH | 6d12547772b57a6da2b25d2188451983 | 2020-07-28 | 2020-07-28 |
| DOMAIN | mnmski.cafe24.com | 2020-07-28 | 2020-07-28 |