疑似APT-C-26(Lazarus)组织通过加密货币钱包推广信息进行攻击活动分析
2023-01-11 • Qihoo360 • Suspected APT-C-26 (Lazarus) attack activity using cryptocurrency wallet promotional information •
360 Advanced Threat Research Institute describes a suspected APT-C-26/Lazarus campaign delivering a malicious ISO themed around promotion of the Somora cryptocurrency wallet to cryptocurrency holders. The ISO contained wallet screenshots and a malicious “Somora Cryptocurrency Wallet” LNK that invoked PowerShell, dropped a decoy PDF, a loader DLL, and encrypted data, then executed the DLL via rundll32. The loader decrypted shellcode that restored and ran a backdoor assessed as a possible NukeSped variant based on code structure, hardcoded C2 behavior, XOR/base64 command handling, and command-execution logic similar to earlier Lazarus samples. The report lists droidnation[.]net/nation.php and long encrypted/hash artifacts as supporting indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 4e058e7d9a3a58b5e61205c73f08399… | 2023-01-11 | 2023-01-11 |
| HASH | c95eaedaafd8041bb0fea414b4ebc0f… | 2023-01-11 | 2023-01-11 |
| DOMAIN | droidnation.net | 2023-01-11 | 2023-01-11 |