Lazarus Operation DreamJob – Ataque a la cadena de suministro de 3CX
2023-05-09 • Ecu CERT •
https://www.ecucert.gob.ec/wp-content/uploads/2023/05/20-Linux.pdf
Attachments
20-Linux.pdf (1 MB)
Lazarus Operation DreamJob activity used a fake HSBC job-offer lure to deliver a native 64-bit Linux ELF downloader, expanding the campaign beyond earlier Windows and macOS targeting. The infection chain starts with a ZIP containing a deceptive file name that appears to be a PDF, opens a decoy document with the system PDF viewer, and uses OdicLoader to fetch the SimplexTea Linux backdoor from OpenDrive. Persistence is established by modifying ~/.bash_profile so the downloaded backdoor runs with Bash while suppressing output. The excerpt links SimplexTea to Lazarus tooling similarities and notes that the Linux payload strengthens the case connecting Lazarus to the 3CX supply-chain compromise, where trojanized Windows and macOS 3CX applications enabled arbitrary payload delivery.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | cc307cfb401d1ae616445e78b610ab7… | 2023-04-20 | 2025-12-17 |
| IPv4 | 23.254.211.230 | 2023-04-20 | 2025-12-17 |
| IPv4 | 172.93.201.88 | 2023-04-20 | 2025-11-09 |
| HASH | 492a643bd1efdaca4ca125ade1b606e… | 2023-04-20 | 2024-12-27 |
| HASH | ce6b4f2a94f0f0f93850f3a2723d1627 | 2023-05-09 | 2023-05-09 |
| HASH | 988ec0c1a4e6a056b92da307c6f68b17 | 2023-05-09 | 2023-05-09 |
| HASH | ab530f284a04fcfc070e237fd2a52e04 | 2023-05-09 | 2023-05-09 |
| HASH | 3a63477a078ce10e53dfb5639e35d74… | 2023-04-20 | 2023-05-09 |
| HASH | 9d8bade2030c93d0a010aa57b90915e… | 2023-04-20 | 2023-05-09 |
| HASH | 3cf7232e5185109321921046d039cf10 | 2023-04-20 | 2023-05-09 |
| HASH | aac5a52b939f3fe792726a13ff7a1747 | 2023-04-20 | 2023-05-09 |
| HASH | 0ca1723afe261cd85b05c9ef424fc50… | 2023-04-20 | 2023-05-09 |
| HASH | f638e5a20114019ad066dd0e856f97f… | 2023-04-20 | 2023-05-09 |
| HASH | f6760fb1f8b019af2304ea6410001b6… | 2023-04-20 | 2023-05-09 |
| HASH | fc41cb8425b6432af8403959bb59430d | 2023-04-20 | 2023-05-09 |
| IPv4 | 38.108.185.79 | 2023-04-20 | 2023-05-09 |
| IPv4 | 38.108.185.115 | 2023-04-20 | 2023-05-09 |
| DOMAIN | journalide.org | 2023-03-29 | 2023-05-09 |