North Korea Turns Against New Targets?!

2019-02-19 Checkpoint

https://research.checkpoint.com/north-korea-turns-against-russian-targets/

Thumbnail for North Korea Turns Against New Targets?!

Check Point observed malicious Office documents uploaded from Russian sources that appeared tailored to Russian organizations and showed intrinsic connections to Lazarus tactics, techniques, and tools, while noting attribution limits. The infection chain used a ZIP containing a benign PDF decoy and a macro-enabled Word document; macros either downloaded a VBS stage from Dropbox-like infrastructure or later skipped directly to downloading the final payload. The VBS stage retrieved a CAB disguised as a JPEG from a compromised Iraqi server and expanded it with Windows expand.exe into the KEYMARBLE Lazarus backdoor. The activity was notable because it suggested North Korea-linked operators targeting Russian entities, an unusual victim set compared with the group’s better-known South Korean, U.S., Japanese, financial, and cryptocurrency operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 088c6157d2bb4238f92ef6818b9b1ff… 2019-02-19 2019-02-19
HASH e89458183cb855118539373177c6737… 2019-02-19 2019-02-19
HASH 4cd5a4782dbed5b8e337ee402f1ef74… 2019-02-19 2019-02-19
IPv4 194.45.8.41 2019-02-19 2019-02-19
IPv4 37.238.135.70 2019-02-19 2019-02-19

Related Actors

Related Reports

« Back