North Korea Turns Against New Targets?!
2019-02-19 • Checkpoint •
https://research.checkpoint.com/north-korea-turns-against-russian-targets/
Check Point observed malicious Office documents uploaded from Russian sources that appeared tailored to Russian organizations and showed intrinsic connections to Lazarus tactics, techniques, and tools, while noting attribution limits. The infection chain used a ZIP containing a benign PDF decoy and a macro-enabled Word document; macros either downloaded a VBS stage from Dropbox-like infrastructure or later skipped directly to downloading the final payload. The VBS stage retrieved a CAB disguised as a JPEG from a compromised Iraqi server and expanded it with Windows expand.exe into the KEYMARBLE Lazarus backdoor. The activity was notable because it suggested North Korea-linked operators targeting Russian entities, an unusual victim set compared with the group’s better-known South Korean, U.S., Japanese, financial, and cryptocurrency operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 088c6157d2bb4238f92ef6818b9b1ff… | 2019-02-19 | 2019-02-19 |
| HASH | e89458183cb855118539373177c6737… | 2019-02-19 | 2019-02-19 |
| HASH | 4cd5a4782dbed5b8e337ee402f1ef74… | 2019-02-19 | 2019-02-19 |
| IPv4 | 194.45.8.41 | 2019-02-19 | 2019-02-19 |
| IPv4 | 37.238.135.70 | 2019-02-19 | 2019-02-19 |