Lazarus Threat Group Attacking Windows Servers to Use as Malware Distribution Points
2023-07-24 • Ahnlab •
ASEC attributed attacks on Windows IIS web servers to Lazarus, reporting that compromised servers were used as malware distribution points for INISAFE CrossWeb EX exploitation. The activity abused vulnerable or poorly managed IIS servers, with malware processes spawned by w3wp.exe and past cases showing web shells, malicious commands, reconnaissance, and possible RDP lateral movement. Lazarus deployed a Themida-packed JuicyPotato privilege-escalation tool as usopriv.exe, checked elevated privileges with whoami commands, and used it to run a DLL loader named usoshared.dat through rundll32. The loader searched for an encrypted data file named {20D1BF68-64EE-489D-9229-95FEFE5F12A4}, expected it to begin with a GIF signature, decrypted configuration and PE content, and executed the payload in memory. ASEC also linked the distribution infrastructure to ongoing attacks against unpatched INISAFE CrossWeb EX installations that attempted to install SCSKAppLink.dll, reinforcing the need for exposed-server hardening and current INITECH product patches.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 280152dfeb6d3123789138c0a396f30d | 2023-07-14 | 2023-07-24 |
| HASH | d0572a2dd4da042f1c64b542e24549d9 | 2023-07-14 | 2023-07-24 |