PyPIを悪用した攻撃グループLazarusのマルウェア拡散活動

2024-02-21 JPCERT Lazarus attack group malware distribution campaign abusing PyPI

https://blogs.jpcert.or.jp/ja/2024/02/lazarus_pypi.html

JPCERT/CC reports that Lazarus published malicious Python packages on PyPI, including pycryptoenv and pycryptoconf, with names chosen to resemble legitimate crypto libraries and catch installation typos. The packages carried XOR-encoded DLL data in test.py and loader code in __init__.py that could decode and run Comebacker, the same malware family previously tied to Lazarus activity against security researchers. The payload created IconCache.db and NTUSER.DAT, executed through rundll32, and sent HTTP POST beacons to C2 paths such as chaingrown.com/manage/manage.asp before loading a Windows executable in memory. JPCERT/CC notes similar Comebacker use in malicious npm packages, indicating Lazarus is abusing multiple package repositories to widen software supply chain exposure.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 63fb47c3b4693409ebadf8a5179141a… 2024-02-21 2025-02-16
DOMAIN fasttet.com 2024-02-21 2024-07-05
IPv4 91.206.178.125 2023-11-04 2024-07-05
DOMAIN blockchain-newtech.com 2023-12-08 2024-05-28
DOMAIN chaingrown.com 2023-12-08 2024-05-28
HASH 173e6bc33efc7a03da06bf5f8686a89… 2024-02-21 2024-02-28
HASH 956d2ed558e3c6e447e3d4424d6b14e… 2024-02-21 2024-02-28
HASH e05142f8375070d1ea25ed3a31404ca… 2024-02-21 2024-02-28
HASH 85c3a2b185f882abd2cc40df5a1a341… 2024-02-21 2024-02-28
HASH 26437bc68133c2ca09bb56bc011dd1b… 2024-02-21 2024-02-28
HASH 6bba8f488c23a0e0f753ac21cd83dde… 2024-02-21 2024-02-28
HASH a8a5411f3696b276aee37eee0d9bed9… 2024-02-21 2024-02-28
HASH 01c5836655c6a4212676c78ec96c0ac… 2024-02-21 2024-02-28
HASH 8fb6d8a5013bd3a36c605031e86fd1f… 2024-02-21 2024-02-28
HASH aec915753612bb003330ce7ffc67cfa… 2024-02-21 2024-02-28
HASH a4e4618b358c92e04fe6b7f94a11487… 2024-02-21 2024-02-28
HASH c56c94e21913b2df4be293001da84c3… 2024-02-21 2024-02-28
HASH 60c080a29f58cf861f5e7c7fc5e5bdd… 2024-02-21 2024-02-28
HASH b4a04b450bb7cae5ea578e79ae9d0f2… 2024-02-21 2024-02-28
HASH 3ab6e6fc888e4df602eff1c5bc24f3e… 2024-02-21 2024-02-28
URL https://fasttet.com/user/agency… 2024-02-21 2024-02-28
URL https://blockchain-newtech.com/… 2023-12-08 2024-02-28
URL https://chaingrown.com/manage/m… 2023-12-08 2024-02-28

Related Reports

« Back