Lazarus Threat Group Exploiting Vulnerability of Korean Finance Security Solution

2023-06-14 Ahnlab

https://asec.ahnlab.com/en/54195/

Thumbnail for Lazarus Threat Group Exploiting Vulnerability of Korean Finance Security Solution

AhnLab reports that Lazarus exploited zero-day vulnerabilities in Korean finance and enterprise security products VestCert and TCO!Stream, expanding beyond previously abused INISAFE CrossWeb EX and MagicLine4NX software. In the VestCert case, users with vulnerable Windows installations who visited a compromised website triggered PowerShell via a third-party library flaw to download and execute malware such as WinSync.dll. For internal propagation, Lazarus used TCO!Stream clients listening on TCP 3511, sending crafted command packets that caused clients to retrieve and run attacker-prepared files from the TCO!Stream server, including loadconf.exe and related backdoor components. ASEC says the vulnerabilities were reported to KISA and patched, but manual updates were required on affected systems.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN swt-keystonevalve.com 2023-06-08 2023-10-27
HASH ec5d5941522d947abd6c9e82e615b46… 2023-06-08 2023-06-14
HASH 8adeeb291b48c97db1816777432d97fd 2023-06-08 2023-06-14
HASH 55f0225d58585d60d486a3cc7eb93de5 2023-06-08 2023-06-14
HASH 3ca6abf845f3528edf58418e5e42a9c… 2023-06-08 2023-06-14
URL http://ksmarathon.com/admin/exc… 2023-06-08 2023-06-14
URL https://www.bcdm.or.kr/board/ty… 2023-06-08 2023-06-14
URL https://swt-keystonevalve.com/d… 2023-06-08 2023-06-14
URL https://www.hmedical.co.kr/incl… 2023-06-08 2023-06-14
URL https://www.gongsilbox.com/boar… 2023-06-08 2023-06-14
URL https://www.coupontreezero.com/… 2023-06-08 2023-06-14
URL http://www.sinae.or.kr/sub01/in… 2023-06-08 2023-06-14
URL https://www.daehang.com/member/… 2023-06-08 2023-06-14
URL https://www.materic.or.kr/files… 2023-06-08 2023-06-14
HASH e7c9bf8bf075487a2d91e0561b86d6f5 2023-03-17 2023-06-14
HASH e73eab80b75887d4e8dd6df33718e3a5 2023-02-15 2023-06-14
HASH 747177aad5aef020b82c6aeabe5b174f 2023-02-15 2023-06-14
HASH 064d696a93a3790bd3a1b8b76baaeef3 2023-02-15 2023-06-14
HASH c09b062841e2c4d46c2e5270182d4272 2023-02-15 2023-06-14
HASH 67d306c163b38a06e98da5711e14c5a7 2023-02-15 2023-06-14
HASH ba741fa4c7b4bb97165644c799e29c99 2023-02-15 2023-06-14

Related Reports

« Back