라자루스 그룹 DLL Side-Loading 기법 이용 (mi.dll)

2022-10-06 • Ahnlab • Using Lazarus Group DLL Side-Loading technique (mi.dll) •

https://asec.ahnlab.com/ko/39648/

Thumbnail for 라자루스 그룹 DLL Side-Loading 기법 이용 (mi.dll)

AhnLab observed Lazarus using DLL side-loading during early intrusion activity to run malicious code through legitimate Microsoft binaries, including wsmprovhost.exe and dfrgui.exe. The intrusion chain involved an older INITECH process distributing the scskapplink.dll backdoor, followed by suspected execution of additional payloads from wsmprovhost.exe when malicious mi.dll was found in the same directories. The malicious mi.dll was based on the open-source BugTrap project, contained an AES-128 encrypted embedded binary, and decrypted and executed the next-stage malware in memory using a key passed at runtime. AhnLab linked the technique to defense evasion because malicious behavior ran inside legitimate process memory, and provided detections for SCSKAppLink.dll and mi.dll as Lazarus-related malware.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 9dc82edb98bc1b1ae89216f0be734a7… 2022-10-06 2022-10-06
HASH 0cc73994988e8dce2a2eeab7bd410fad 2022-10-06 2022-10-06
HASH 54b0454163b25a38368e518e1687de5b 2022-10-06 2022-10-06
HASH 348ff9e7a8d17e76ab4e8e3f3f6e357… 2022-10-06 2022-10-06

Related Actors

Related Reports

« Back