Log4Shell 취약점을 악용하는 Lazarus 그룹 (NukeSped)

2022-05-12 Ahnlab Lazarus group (NukeSped) exploiting Log4Shell vulnerability

https://asec.ahnlab.com/ko/34107/

Thumbnail for Log4Shell 취약점을 악용하는 Lazarus 그룹 (NukeSped)

AhnLab observed suspected Lazarus activity exploiting CVE-2021-44228 in unpatched VMware Horizon servers used for remote work and cloud infrastructure operations in South Korea. The intrusion deployed a NukeSped backdoor variant associated with Lazarus since around 2020, with C++ class artifacts, DES-protected internal strings, RC4-encrypted C2 lists and traffic, and SSL-like handshake strings used to validate command-and-control servers. NukeSped supported operator commands including keylogging, screen capture, file and shell operations, port forwarding, and newly observed USB dump and webcam modules. The attackers also installed credential and information stealers targeting browsers, email clients, and recent Office/HWP files, then ran discovery and account-management commands such as ipconfig, query user, domain admin enumeration, and administrator-group modification that could support lateral movement. Reported infrastructure included 185.29.8[.]18, 84.38.133[.]145, 84.38.133[.]16, and mail.usengineergroup[.]com, while separate logs showed earlier Log4Shell exploitation on the same environment by Jin Miner activity.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 131fc4375971af391b459de33f81c253 2022-05-12 2023-02-10
HASH 830bc975a04ab0f62bfedf27f7aca673 2022-05-12 2023-02-10
HASH 85995257ac07ae5a6b4a86758a2283d7 2022-05-12 2023-02-10
HASH 87a6bda486554ab16c82bdfb12452e8b 2022-05-12 2023-02-10
HASH 827103a6b6185191fd5618b7e82da292 2022-05-12 2023-02-10
HASH 1875f6a68f70bee316c8a6eda9ebf8de 2022-04-28 2023-02-10
HASH 47791bf9e017e3001ddc68a7351ca2d6 2022-04-28 2023-02-10
IPv4 84.38.133.145 2022-05-12 2022-09-08
HASH c2412d00eb3b4bccae0d98e9be4d92bb 2022-05-12 2022-05-12
HASH 8c8a38f5af62986a45f2ab4f44a0b983 2022-05-12 2022-05-12
HASH 7ef97450e84211f9f35d45e1e6ae1481 2022-05-12 2022-05-12
HASH dd4b8a2dc73a29bc7a598148eb8606bb 2022-05-12 2022-05-12
HASH 7a19c59c4373cadb4556f7e30ddd91ac 2022-05-12 2022-05-12
URL http://iosk.org/pms/jin.zip 2022-05-12 2022-05-12
URL http://iosk.org/pms/add.bat 2022-05-12 2022-05-12
URL http://iosk.org/pms/mad.bat 2022-05-12 2022-05-12
URL http://iosk.org/pms/jin-6.zip 2022-05-12 2022-05-12
DOMAIN iosk.org 2022-05-12 2022-05-12
IPv4 185.29.8.18 2022-05-12 2022-05-12
IPv4 84.38.133.16 2022-05-12 2022-05-12
DOMAIN mail.usengineergroup.com 2022-04-28 2022-05-12

Related Actors

Related Reports

« Back