疑似Lazarus针对双平台的攻击活动披露

2019-11-04 • Qianxin • Suspected Lazarus attack activities targeting dual platforms disclosed •

https://ti.qianxin.com/blog/articles/suspected-lazarus-disclosure-of-attacks-on-dual-platforms/

Thumbnail for 疑似Lazarus针对双平台的攻击活动披露

QiAnXin’s threat intelligence team found Lazarus-linked attack samples for both Windows and macOS, including a Windows lure built around a psychological test that prompted users to enable macros. The Windows sample released and executed a PowerShell backdoor from the temp directory, hard-coded three C2 servers, collected host information, and supported command-driven file download and execution. A related macOS sample used a fake Flash Player component, extracted and installed a hidden .FlashUpdateCheck payload through a launchctl-loaded plist for persistence, and used backdoor functions broadly consistent with the PowerShell implant. The report attributes the activity to Lazarus based on backdoor and TTP analysis and highlights the group’s continuing ability to conduct multi-platform operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d91c233b2f1177357387c29d92bd3f2… 2019-11-04 2020-07-27
HASH 6f7a5f1d52d3bfc6f175bf2bbb665e4… 2019-11-04 2019-11-20
URL https://craypot.live/board.php 2019-11-04 2019-11-20
URL https://crabbedly.club/board.php 2019-11-04 2019-11-20
DOMAIN indagator.club 2019-11-04 2019-11-20
DOMAIN craypot.live 2019-11-04 2019-11-20
DOMAIN crabbedly.club 2019-11-04 2019-11-20
HASH a7ff0dfc2456baa80e6291619e0ca48… 2019-11-04 2019-11-12
URL http://indagator.club/board.php 2019-11-04 2019-11-04

Related Actors

Related Reports

« Back