Threat Actor targeted attack against Finance and Investment industry
2021-11-04 • NSHC •
NSHC ThreatRecon reports a long-running campaign targeting finance and investment-sector organizations in multiple countries with malicious Word documents disguised as investment, NDA, and company-related files. The documents used remote template injection rather than embedded macros, causing Office to contact attacker-controlled HTTPS C2 domains such as lundbergs[.]cc and download a malicious template or payload only after the target opened the lure. The infrastructure used many domains on HOSTWINDS-hosted address space and rotating multi-domain TLS certificates, with detections referencing Lazarus APT maldoc certificates. The source finds some links to a state-sponsored hacking group but cautions that the available evidence is insufficient to definitively attribute the activity to a government-backed financial theft operation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | be17fdbe8d7e674ec397cd457dda1b7… | 2021-11-04 | 2021-11-04 |
| URL | https://lundbergs.cc/6cjmh0mczu… | 2021-11-04 | 2021-11-04 |