Lazarus on the hunt for big game

2020-07-28 Kaspersky

https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/

Thumbnail for Lazarus on the hunt for big game

Kaspersky linked VHD ransomware operations to Lazarus after incident-response evidence showed a MATA framework backdoor in the same victim environment and no sign of another actor during the intrusion. One European incident used a victim-specific spreading utility with administrative credentials and IP addresses to brute-force SMB, copy the ransomware, and execute it through WMI. A later case likely began with opportunistic VPN exploitation, privilege escalation, a backdoor deployment, Active Directory takeover, and network-wide VHD staging through a Python downloader within about 10 hours. The ransomware used AES-256 in ECB mode and RSA-2048, while the report lists MATA command-and-control infrastructure and VHD hashes, making the activity notable as a Lazarus-run targeted ransomware operation rather than a typical outsourced cybercrime ecosystem case.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 104.232.71.7 2020-07-22 2021-03-23
IPv4 172.93.184.62 2020-07-22 2021-03-23
IPv4 23.227.199.69 2020-07-22 2021-03-23
HASH ccc6026acf7eadada9adaccab70ca4d6 2020-07-28 2020-07-28
HASH dd00a8610bb84b54e99ae8099db1fc20 2020-07-28 2020-07-28
HASH d0806c9d8bcea0bd47d80fa004744d7d 2020-07-28 2020-07-28
HASH efd4a87e7c5dcbb64b7313a13b4b1012 2020-07-28 2020-07-28
HASH 6d12547772b57a6da2b25d2188451983 2020-07-28 2020-07-28
DOMAIN mnmski.cafe24.com 2020-07-28 2020-07-28

Related Actors

Related Reports

« Back