암호화폐 거래자를 노린 Lazarus APT 공격 가속화

2019-07-02 • ESTSecurity • Lazarus APT attacks targeting cryptocurrency traders accelerate •

https://blog.alyac.co.kr/2397

Thumbnail for 암호화폐 거래자를 노린 Lazarus APT 공격 가속화

ESRC reports a run of APT activity against South Korea involving Lazarus, Kimsuky, and Geumseong121, with the highlighted Lazarus case targeting cryptocurrency-related individuals through a malicious HWP document disguised as a student project report. The attachment used an embedded malicious PostScript stream and XOR-decoded shellcode to attempt downloads from command-and-control URLs hosted under compromised WordPress paths. A later HWP variant, disguised as an air-conditioner maintenance document, reused the same structure and execution flow while switching to calderonflooring[.]com-hosted payload URLs. The activity matters because the same South Korea-focused threat landscape combined espionage-oriented targeting with financially motivated attacks against cryptocurrency users and exchanges.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN darvishkhan.net 2019-07-02 2021-04-14
URL https://darvishkhan.net/wp-cont… 2019-07-02 2020-07-06
HASH f88a9123c1e5c6ad54969337155ceb1… 2019-07-02 2019-07-02
HASH bb157732cb52b6d30c624dfb111d0264 2019-07-02 2019-07-02
HASH 1fd70d399d616bfac82a2d3ae69ec3f… 2019-07-02 2019-07-02
URL https://www.calderonflooring.co… 2019-07-02 2019-07-02
URL https://darvishkhan.net/wp-cont… 2019-07-02 2019-07-02
URL https://www.calderonflooring.co… 2019-07-02 2019-07-02

Related Actors

Related Reports

« Back