North Korea’s Lazarus: their initial access trade-craft using social media and social engineering
2022-05-05 • NCCGroup •
NCC Group details Lazarus initial-access activity built around LinkedIn impersonation, WhatsApp contact, and job-themed ZIP files containing malicious Office documents. The lure infrastructure included global-job[.]org, a domain likely chosen to imitate a legitimate recruitment site, and the macro execution path called rundll32.exe against C:\ProgramData\packages.mdb before suspected LCPDot deployment. Investigators recovered a large, timestomped downloader placed at C:\ProgramData\Oracle\Java\JavaPackage.dll and persisted through a daily scheduled task named “Windows Java Vpn Interface.” The LCPDot variant registers infected hosts with C2 using encoded session data, requests a second-stage payload, decrypts it with RC4-derived key material, and executes it in memory; listed infrastructure includes compromised domains and 13[.]88[.]245[.]250.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | thefrostery.co.uk | 2022-05-05 | 2024-02-19 |
| DOMAIN | global-job.org | 2022-05-05 | 2022-08-11 |
| HASH | f4e314e8007104974681d92267673ac… | 2022-05-05 | 2022-05-05 |
| HASH | d25a4f20c0b9d982d63fc0135798384… | 2022-05-05 | 2022-05-05 |
| HASH | 0a6f762a47557e369db8655a0d14ab0… | 2022-05-05 | 2022-05-05 |
| HASH | afbcb626b770b1f87ff9b5721d2f3235 | 2022-05-05 | 2022-05-05 |
| HASH | fd02e0f5fcf97022ac266a3e5488808… | 2022-05-05 | 2022-05-05 |
| HASH | 49c2821a940846bdacb8a3457be4663c | 2022-05-05 | 2022-05-05 |
| DOMAIN | globaljobs.org | 2022-05-05 | 2022-05-05 |
| DOMAIN | ats.apvit.com | 2022-05-05 | 2022-05-05 |
| DOMAIN | bugs-hpsm.mobitechnologies.com | 2022-05-05 | 2022-05-05 |
| IPv4 | 13.88.245.250 | 2022-05-05 | 2022-05-05 |
| DOMAIN | shoppingbagsdirect.com | 2022-04-18 | 2022-05-05 |