THE LAZARUS’ GAZE TO THE WORLD: WHAT IS BEHIND THE FIRST STONE ?

2019-11-05 Telsy

https://web.archive.org/web/20200605214110/https://blog.telsy.com/lazarus-gate/

Thumbnail for THE LAZARUS’ GAZE TO THE WORLD: WHAT IS BEHIND THE FIRST STONE ?

Telsy TRT analyzed a likely Lazarus operation that began from a spoofed email delivering a malicious document to an Italian banking and financial institution. The document carried architecture-specific first-stage payloads and dropped a library under a Microsoft ThumbNail path, then used rundll32 and a Startup-folder shortcut for persistence. The first stage performed system reconnaissance and HTTP POST beacons to command-and-control scripts hosted on compromised legitimate sites, with collected victim data compressed, encrypted, and logged by the backend. The report frames Lazarus/APT38/Hidden Cobra attribution as likely and focuses on the early kill chain, victim filtering, and second-stage delivery controls.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN curiofirenze.com 2019-11-05 2021-02-25
HASH 26a2fa7b45a455c311fd57875d8231c… 2019-11-05 2020-05-15
HASH ec254c40abff00b104a949f07b7b642… 2019-11-05 2020-05-15
HASH 1a172d92638e6fdb2858dcca7a78d4b… 2019-11-05 2019-11-12
IPv4 193.70.64.163 2019-11-05 2019-11-12
HASH adf86d77eb4064c52a3e4fb3f1c3218… 2019-11-05 2019-11-05
HASH b018639e9a5f3b2b9c257b83ee51a3f… 2019-11-05 2019-11-05

Related Actors

Related Reports

« Back