LolZarus: Lazarus Group Incorporating Lolbins into Campaigns
2022-02-08 • Qualys •
Qualys analyzed a Lazarus campaign, dubbed LolZarus, that used Lockheed Martin-themed job phishing documents against defense-sector targets. The documents shared author and macro-flow traits with earlier Lazarus lures, decoded embedded shellcode, hijacked execution through WMVCORE.dll and the KernelCallbackTable, and displayed a decoy job document. The payload created a C:\WMAuthorization staging directory, scheduled periodic VBS-based beacons, and used renamed LOLBins such as mshta/wscript, with related variants using wuauclt, wmic, and pcalua. Reported infrastructure included markettrendingcenter.com for decoy retrieval and beaconing, while the campaign demonstrated Lazarus’ continued use of legitimate Windows binaries for stealthy execution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | markettrendingcenter.com | 2022-01-27 | 2023-10-04 |
| DOMAIN | lm-career.com | 2022-01-27 | 2023-10-04 |
| HASH | e87b575b2ddfb9d4d692e3b8627e3921 | 2022-02-08 | 2022-02-08 |
| HASH | 712a8e4d3ce36d72ff74b785aaf18cb0 | 2022-02-08 | 2022-02-08 |
| HASH | 490c885dc7ba0f32c07ddfe02a04bbb9 | 2022-02-08 | 2022-02-08 |
| HASH | 3f326da2affb0f7f2a4c5c95ffc660cc | 2022-02-08 | 2022-02-08 |
| HASH | f2a0e9034d67f8200993c4fa8e4f5d15 | 2022-02-08 | 2022-02-08 |
| HASH | a27a9324d282d920e495832933d486ee | 2022-02-08 | 2022-02-08 |
| URL | https://markettrendingcenter.co… | 2022-02-08 | 2022-02-08 |
| URL | https://markettrendingcenter.co… | 2022-01-27 | 2022-02-08 |
| URL | https://www.advantims.com/GfxCP… | 2021-01-23 | 2022-02-08 |
| DOMAIN | advantims.com | 2021-01-23 | 2022-02-08 |