Lazarus targets nuclear-related organization with new malware

2024-12-19 Kaspersky

https://securelist.com/lazarus-new-malware/115059/

Thumbnail for Lazarus targets nuclear-related organization with new malware

Kaspersky attributes a DeathNote, also known as Operation DreamJob, attack against at least two employees at the same nuclear-related organization to Lazarus. The delivery used IT skills-assessment archives tied to aerospace and defense job lures, including trojanized VNC utilities, likely ISO or ZIP files, AmazonVNC.exe, and DLL side-loading through UltraVNC vnclang.dll. The chain loaded Ranid Downloader, MISTPEN, RollMid, LPEClient, CookieTime, Charamel Loader, ServiceChanger, and CookiePlus, then supported persistence and lateral movement from Host A to Host C. The case shows Lazarus changing the post-lure infection chain while keeping the fake recruiter and remote-access-tool pattern used in DreamJob operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH cf8c0999c148d764667b1a269c28bdcb 2024-12-19 2024-12-23
HASH 4c4abe85a1c68ba8385d2cb928ac5646 2024-12-19 2024-12-23
HASH 00a2952a279f9c84ae71367d5b8990c1 2024-12-19 2024-12-23
HASH 5eac943e23429a77d9766078e760fc0b 2024-12-19 2024-12-23
HASH 80ab98c10c23b7281a2bf1489fc98c0d 2024-12-19 2024-12-23
HASH 778942b891c4e2f3866c6a3c09bf74f4 2024-12-19 2024-12-19
HASH 57453d6d918235adb66b896e5ab252b6 2024-12-19 2024-12-19
HASH d966af7764dfeb8bf2a0feea503be0fd 2024-12-19 2024-12-19
HASH 1315027e1c536d488fe63ea0a528b52d 2024-12-19 2024-12-19
HASH c6323a40d1aa5b7fe95951609fb2b524 2024-12-19 2024-12-19
HASH fdc5505d7277e0bf7b299957eadfd931 2024-12-19 2024-12-19
HASH bf5a3505273391c5380b3ab545e400eb 2024-12-19 2024-12-19
HASH 739875852198ecf4d734d41ef1576774 2024-12-19 2024-12-19
HASH 37973e29576db8a438250a156977ccdf 2024-12-19 2024-12-19
HASH e0dd4afb965771f8347549fd93423985 2024-12-19 2024-12-19
HASH 2b2cbc8de3bdefcd7054f56b70ef58b4 2024-12-19 2024-12-19
HASH e6a1977ecce2ced5a471baa52492d9f3 2024-12-19 2024-12-19
HASH b0e795853b655682483105e353b9cd54 2024-12-19 2024-12-19
HASH 0ee8246de53c20a424fb08096922db08 2024-12-19 2024-12-19

Related Actors

Related Reports

« Back