Paleontology: The Unknown Origins of Lazarus malware

2018-10-31 Intezer

https://www.intezer.com/paleontology-the-unknown-origins-of-lazarus-malware/

Thumbnail for Paleontology: The Unknown Origins of Lazarus malware

Intezer traces part of Lazarus malware lineage to CasperPhpTrojan, an open-source RAT published on a Chinese project site, after VirusTotal samples from 2016 matched Lazarus-related code signatures. The analysis found overlap with RedGambler code genes, an internal module name DllTroy.dll, and reused strings associated with Operation Troy and Prioxer. By compiling and comparing CasperPhpTrojan source against Lazarus binaries, Intezer identified shared implementation patterns such as HTTP header construction and GetProcAddress/LoadLibrary usage. The report includes hashes and infrastructure such as ready-jetkorea[.]com and plsong[.]com URLs that can support further pivoting. The finding matters because it reframes some Lazarus code reuse as possible adaptation of public RAT source code rather than exclusively original DPRK-developed tooling.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN pudn.com 2018-10-31 2020-08-05
HASH d1cf03fbcb6471d44b914c272082158… 2018-10-31 2018-10-31
HASH f4b7b36e9c940937748d5bba3beb82b… 2018-10-31 2018-10-31
HASH 4915f53221dc7786710a7a82a9cb00c… 2018-10-31 2018-10-31
HASH c62ec66e45098d2c41bfd7a674a5f76… 2018-10-31 2018-10-31
HASH 458ffcc41959599f8dab1fd4366c9a5… 2018-10-31 2018-10-31
HASH 6724c041fe0df61a619006bf1df4a75… 2018-10-31 2018-10-31
HASH ec73fe2ecc2e0425e4aeb1f01581b50… 2018-10-31 2018-10-31
HASH 1b6a1320fba00dd2e56e35cf6f11f94… 2018-10-31 2018-10-31
HASH 926a2e8c2baa90d504d48c0d50ca73e… 2018-10-31 2018-10-31
HASH 068b89e2ec5655d006f2788ea328e5f… 2018-10-31 2018-10-31
URL http://ready-jetkorea.com/data/… 2018-10-31 2018-10-31
URL http://plsong.com/xe/addons/cou… 2018-10-31 2018-10-31
DOMAIN ready-jetkorea.com 2018-10-31 2018-10-31
DOMAIN plsong.com 2018-10-31 2018-10-31

Related Actors

Related Reports

« Back