Lazarus Targets Chemical Sector

2022-04-14 Symantec

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lazarus-dream-job-chemical

Thumbnail for Lazarus Targets Chemical Sector

Symantec observed the North Korea-linked Lazarus group targeting South Korean chemical-sector organizations in activity assessed as a continuation of Operation Dream Job, tracked by Symantec as Pompilus. The campaign used fake job-offer lures that led to malicious HTM files, DLL injection into INISAFE Web EX Client, and Trojanized signed tools such as ComparePlus and XZ Utils components with malicious exports. Follow-on activity included shellcode loaders, C2 communication using the "prd_fld=racket" parameter, credential dumping from registry hives, WMI-based lateral movement, scheduled-task persistence, and deployment of tools such as SiteShoter, IP Logger, WakeOnLAN, FastCopy, and FTP under MagicLine. Symantec assessed the chemical-sector targeting as likely intended to support North Korea’s acquisition of intellectual property in that field.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 79b7964bde948b70a7c3869d34fe5d5… 2022-04-14 2022-09-26
HASH 7aa62af5a55022fd89b3f0c025ea508… 2022-04-14 2022-09-26
HASH 164f6a8f7d2035ea47514ea84294348… 2022-04-14 2022-04-14
HASH 18686d04f22d3b593dd78078c9db0ac… 2022-04-14 2022-04-14
HASH f29d386bdf77142cf2436797fba1f8b… 2022-04-14 2022-04-14
HASH 1cb8ea3e959dee988272904dbb134da… 2022-04-14 2022-04-14
HASH ff167e09b3b7ad6ed1dead9ee5b4747… 2022-04-14 2022-04-14
HASH f8995634b102179a5d3356c6f353cb3… 2022-04-14 2022-04-14
HASH 8769912b9769b4c11aabc523a699d02… 2022-04-14 2022-04-14
HASH 2dd29b36664b28803819054a59934f7… 2022-04-14 2022-04-14
HASH 67f1db122ad8f01e5faa60e2facf16c… 2022-04-14 2022-04-14
HASH 5e7edc8f1c652f53a6d2eabfbd92527… 2022-04-14 2022-04-14
HASH 4a2236596e92fa704d8550c56598855… 2022-04-14 2022-04-14
HASH 61e305d6325b1ffb6de329f1eb5b3a6… 2022-04-14 2022-04-14
HASH 4277fcaada4939b76a3df4515b7f748… 2022-04-14 2022-04-14
HASH 7491f298e27eb7ce7ebbf8821527667… 2022-04-14 2022-04-14
HASH 4446efafb4b757f7fc20485198236be… 2022-04-14 2022-04-14
HASH e31af5131a095fbc884c56068e19b0c… 2022-04-14 2022-04-14
HASH 54029bd4fcc24551564942561a60b90… 2022-04-14 2022-04-14
HASH d815fb8febaf113f3cec82f552dfec1… 2022-04-14 2022-04-14
HASH 8aace6989484b88abc7e3ec6f70b60d… 2022-04-14 2022-04-14
HASH f7359490d6c141ef7a9ee2c03dbbd6c… 2022-04-14 2022-04-14
HASH 32bfdf1744077c9365a811d66a6ea15… 2022-04-14 2022-04-14
HASH e1997d1c3d84c29e02b1b7b726a0d0f… 2022-04-14 2022-04-14
HASH ef987baef9a1619454b14e1fec64283… 2022-04-14 2022-04-14
HASH 942489ce7dce87f7888322a0e56b5e3… 2022-04-14 2022-04-14
HASH 56da872e8b0f145417defd4a37f357b… 2022-04-14 2022-04-14
HASH 5f20cc6a6a82b940670a0f89eda5d68… 2022-04-14 2022-04-14
HASH bdb76c8d0afcd6b57c8f1fa644765b9… 2022-04-14 2022-04-14
HASH 48f3ead8477f3ef16da6b74dadc8966… 2022-04-14 2022-04-14
HASH 35de8163c433e8d9bf6a0097a506e3a… 2022-04-14 2022-04-14
URL http://happy.nanoace.co.kr/Cont… 2022-04-14 2022-04-14
URL https://mariamchurch.com/board/… 2022-04-14 2022-04-14
URL https://www.aumentarelevisite.c… 2022-04-14 2022-04-14
DOMAIN mariamchurch.com 2022-04-14 2022-04-14
DOMAIN happy.nanoace.co.kr 2022-04-14 2022-04-14
IPv4 61.81.50.174 2022-04-14 2022-04-14
IPv4 52.79.118.195 2022-04-14 2022-04-14
HASH a881c9f40c1a5be3919cafb2ebe2bb5… 2021-07-08 2022-04-14

Related Actors

Related Reports

« Back