疑似Lazarus(APT-Q-1)涉及npm包供应链的攻击样本分析

2023-12-08 • Qianxin • Analysis of attack samples suspected of Lazarus (APT-Q-1) involving npm package supply chain •

https://mp.weixin.qq.com/s/f5YE12w3x3wad5EO0EB53Q

Thumbnail for 疑似Lazarus(APT-Q-1)涉及npm包供应链的攻击样本分析

QiAnXin analyzes downloader samples tied to an npm package supply-chain poisoning incident that it assesses as likely Lazarus based on code overlap with historical Lazarus samples and the group's prior use of supply-chain attacks. The loader decrypts embedded PE and ZIP data, drops IconCache.db and NTUSER.DAT under the user's Roaming Microsoft paths, and establishes persistence through scheduled tasks, HKCU Run, or the Startup folder. The main downloader contacts C2 to request payload metadata, downloads numbered payloads, verifies MD5 hashes, decrypts PE content in memory, and executes specified export functions through rundll32-style loading. The report links the activity to infrastructure including 91.206.178.125, blockchain-newtech.com, chaingrown.com, and 156.236.76.9, while comparing the loading method and constants with earlier Lazarus-linked Comebacker and 3CX-related research.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 00433ebf3b21c1c055d4ab8a599d3e8… 2023-12-08 2025-02-16
IPv4 91.206.178.125 2023-11-04 2024-07-05
DOMAIN blockchain-newtech.com 2023-12-08 2024-05-28
DOMAIN chaingrown.com 2023-12-08 2024-05-28
HASH 01c5836655c6a4212676c78ec96c0ac… 2023-12-08 2024-02-28
HASH aec915753612bb003330ce7ffc67cfa… 2023-12-08 2024-02-28
URL https://blockchain-newtech.com/… 2023-12-08 2024-02-28
URL https://chaingrown.com/manage/m… 2023-12-08 2024-02-28
IPv4 103.179.142.171 2023-11-04 2024-01-19
HASH 0dfa5d43fed3bcf68220d51a01d9d56… 2023-12-08 2023-12-08
HASH b4c8c149005a43ae043038d4d62631d… 2023-12-08 2023-12-08
HASH 8dac44ff0890828201b24d5812c21a0… 2023-12-08 2023-12-08
IPv4 156.236.76.9 2023-12-08 2023-12-08

Related Actors

Related Reports

« Back