PyPIを悪用した攻撃グループLazarusのマルウェア拡散活動
2024-02-21 • JPCERT • Lazarus attack group malware distribution campaign abusing PyPI •
JPCERT/CC reports that Lazarus published malicious Python packages on PyPI, including pycryptoenv and pycryptoconf, with names chosen to resemble legitimate crypto libraries and catch installation typos. The packages carried XOR-encoded DLL data in test.py and loader code in __init__.py that could decode and run Comebacker, the same malware family previously tied to Lazarus activity against security researchers. The payload created IconCache.db and NTUSER.DAT, executed through rundll32, and sent HTTP POST beacons to C2 paths such as chaingrown.com/manage/manage.asp before loading a Windows executable in memory. JPCERT/CC notes similar Comebacker use in malicious npm packages, indicating Lazarus is abusing multiple package repositories to widen software supply chain exposure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 63fb47c3b4693409ebadf8a5179141a… | 2024-02-21 | 2025-02-16 |
| DOMAIN | fasttet.com | 2024-02-21 | 2024-07-05 |
| IPv4 | 91.206.178.125 | 2023-11-04 | 2024-07-05 |
| DOMAIN | blockchain-newtech.com | 2023-12-08 | 2024-05-28 |
| DOMAIN | chaingrown.com | 2023-12-08 | 2024-05-28 |
| HASH | 173e6bc33efc7a03da06bf5f8686a89… | 2024-02-21 | 2024-02-28 |
| HASH | 956d2ed558e3c6e447e3d4424d6b14e… | 2024-02-21 | 2024-02-28 |
| HASH | e05142f8375070d1ea25ed3a31404ca… | 2024-02-21 | 2024-02-28 |
| HASH | 85c3a2b185f882abd2cc40df5a1a341… | 2024-02-21 | 2024-02-28 |
| HASH | 26437bc68133c2ca09bb56bc011dd1b… | 2024-02-21 | 2024-02-28 |
| HASH | 6bba8f488c23a0e0f753ac21cd83dde… | 2024-02-21 | 2024-02-28 |
| HASH | a8a5411f3696b276aee37eee0d9bed9… | 2024-02-21 | 2024-02-28 |
| HASH | 01c5836655c6a4212676c78ec96c0ac… | 2024-02-21 | 2024-02-28 |
| HASH | 8fb6d8a5013bd3a36c605031e86fd1f… | 2024-02-21 | 2024-02-28 |
| HASH | aec915753612bb003330ce7ffc67cfa… | 2024-02-21 | 2024-02-28 |
| HASH | a4e4618b358c92e04fe6b7f94a11487… | 2024-02-21 | 2024-02-28 |
| HASH | c56c94e21913b2df4be293001da84c3… | 2024-02-21 | 2024-02-28 |
| HASH | 60c080a29f58cf861f5e7c7fc5e5bdd… | 2024-02-21 | 2024-02-28 |
| HASH | b4a04b450bb7cae5ea578e79ae9d0f2… | 2024-02-21 | 2024-02-28 |
| HASH | 3ab6e6fc888e4df602eff1c5bc24f3e… | 2024-02-21 | 2024-02-28 |
| URL | https://fasttet.com/user/agency… | 2024-02-21 | 2024-02-28 |
| URL | https://blockchain-newtech.com/… | 2023-12-08 | 2024-02-28 |
| URL | https://chaingrown.com/manage/m… | 2023-12-08 | 2024-02-28 |