Log4Shell 취약점을 악용하는 Lazarus 그룹 (NukeSped)
2022-05-12 • Ahnlab • Lazarus group (NukeSped) exploiting Log4Shell vulnerability •
AhnLab observed suspected Lazarus activity exploiting CVE-2021-44228 in unpatched VMware Horizon servers used for remote work and cloud infrastructure operations in South Korea. The intrusion deployed a NukeSped backdoor variant associated with Lazarus since around 2020, with C++ class artifacts, DES-protected internal strings, RC4-encrypted C2 lists and traffic, and SSL-like handshake strings used to validate command-and-control servers. NukeSped supported operator commands including keylogging, screen capture, file and shell operations, port forwarding, and newly observed USB dump and webcam modules. The attackers also installed credential and information stealers targeting browsers, email clients, and recent Office/HWP files, then ran discovery and account-management commands such as ipconfig, query user, domain admin enumeration, and administrator-group modification that could support lateral movement. Reported infrastructure included 185.29.8[.]18, 84.38.133[.]145, 84.38.133[.]16, and mail.usengineergroup[.]com, while separate logs showed earlier Log4Shell exploitation on the same environment by Jin Miner activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 131fc4375971af391b459de33f81c253 | 2022-05-12 | 2023-02-10 |
| HASH | 830bc975a04ab0f62bfedf27f7aca673 | 2022-05-12 | 2023-02-10 |
| HASH | 85995257ac07ae5a6b4a86758a2283d7 | 2022-05-12 | 2023-02-10 |
| HASH | 87a6bda486554ab16c82bdfb12452e8b | 2022-05-12 | 2023-02-10 |
| HASH | 827103a6b6185191fd5618b7e82da292 | 2022-05-12 | 2023-02-10 |
| HASH | 1875f6a68f70bee316c8a6eda9ebf8de | 2022-04-28 | 2023-02-10 |
| HASH | 47791bf9e017e3001ddc68a7351ca2d6 | 2022-04-28 | 2023-02-10 |
| IPv4 | 84.38.133.145 | 2022-05-12 | 2022-09-08 |
| HASH | c2412d00eb3b4bccae0d98e9be4d92bb | 2022-05-12 | 2022-05-12 |
| HASH | 8c8a38f5af62986a45f2ab4f44a0b983 | 2022-05-12 | 2022-05-12 |
| HASH | 7ef97450e84211f9f35d45e1e6ae1481 | 2022-05-12 | 2022-05-12 |
| HASH | dd4b8a2dc73a29bc7a598148eb8606bb | 2022-05-12 | 2022-05-12 |
| HASH | 7a19c59c4373cadb4556f7e30ddd91ac | 2022-05-12 | 2022-05-12 |
| URL | http://iosk.org/pms/jin.zip | 2022-05-12 | 2022-05-12 |
| URL | http://iosk.org/pms/add.bat | 2022-05-12 | 2022-05-12 |
| URL | http://iosk.org/pms/mad.bat | 2022-05-12 | 2022-05-12 |
| URL | http://iosk.org/pms/jin-6.zip | 2022-05-12 | 2022-05-12 |
| DOMAIN | iosk.org | 2022-05-12 | 2022-05-12 |
| IPv4 | 185.29.8.18 | 2022-05-12 | 2022-05-12 |
| IPv4 | 84.38.133.16 | 2022-05-12 | 2022-05-12 |
| DOMAIN | mail.usengineergroup.com | 2022-04-28 | 2022-05-12 |