Lazarus Threat Group Attacking Windows Servers to Use as Malware Distribution Points

2023-07-24 Ahnlab

https://asec.ahnlab.com/en/55369/

Thumbnail for Lazarus Threat Group Attacking Windows Servers to Use as Malware Distribution Points

ASEC attributed attacks on Windows IIS web servers to Lazarus, reporting that compromised servers were used as malware distribution points for INISAFE CrossWeb EX exploitation. The activity abused vulnerable or poorly managed IIS servers, with malware processes spawned by w3wp.exe and past cases showing web shells, malicious commands, reconnaissance, and possible RDP lateral movement. Lazarus deployed a Themida-packed JuicyPotato privilege-escalation tool as usopriv.exe, checked elevated privileges with whoami commands, and used it to run a DLL loader named usoshared.dat through rundll32. The loader searched for an encrypted data file named {20D1BF68-64EE-489D-9229-95FEFE5F12A4}, expected it to begin with a GIF signature, decrypted configuration and PE content, and executed the payload in memory. ASEC also linked the distribution infrastructure to ongoing attacks against unpatched INISAFE CrossWeb EX installations that attempted to install SCSKAppLink.dll, reinforcing the need for exposed-server hardening and current INITECH product patches.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 280152dfeb6d3123789138c0a396f30d 2023-07-14 2023-07-24
HASH d0572a2dd4da042f1c64b542e24549d9 2023-07-14 2023-07-24

Related Reports

« Back