The Lazarus Group Strikes Again - Or is it an Imposter? The Latest CVE-2018-4878 Attack

2018-03-02 Morphisec

http://blog.morphisec.com/the-lazarus-group-strikes-again-or-is-it-an-imposter-the-latest-cve-2018-4878-attack

Morphisec analyzed a Word document named AGREEMENT.docx that exploited Flash vulnerability CVE-2018-4878 to execute code and download a DLL payload from a likely compromised domain. The exploit included both 32-bit and 64-bit implementations, unlike a prior campaign that used only a 32-bit variant. The payload and exploit shared several traits associated with past Lazarus activity, including string encryption, network protocol patterns, and Korean-language resource directory references, while the authors noted that weak obfuscation and missing validation could indicate deliberate false-flagging. The report is relevant because it documents active weaponization of CVE-2018-4878 with Lazarus-like tradecraft while explicitly cautioning against overconfident attribution.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 41b541412154d9e7ce46f952e02dec70 2018-03-02 2018-03-02

Related Actors

Related Reports

« Back