암호화폐 거래자를 노린 Lazarus APT 공격 가속화
2019-07-02 • ESTSecurity • Lazarus APT attacks targeting cryptocurrency traders accelerate •
ESRC reports a run of APT activity against South Korea involving Lazarus, Kimsuky, and Geumseong121, with the highlighted Lazarus case targeting cryptocurrency-related individuals through a malicious HWP document disguised as a student project report. The attachment used an embedded malicious PostScript stream and XOR-decoded shellcode to attempt downloads from command-and-control URLs hosted under compromised WordPress paths. A later HWP variant, disguised as an air-conditioner maintenance document, reused the same structure and execution flow while switching to calderonflooring[.]com-hosted payload URLs. The activity matters because the same South Korea-focused threat landscape combined espionage-oriented targeting with financially motivated attacks against cryptocurrency users and exchanges.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | darvishkhan.net | 2019-07-02 | 2021-04-14 |
| URL | https://darvishkhan.net/wp-cont… | 2019-07-02 | 2020-07-06 |
| HASH | f88a9123c1e5c6ad54969337155ceb1… | 2019-07-02 | 2019-07-02 |
| HASH | bb157732cb52b6d30c624dfb111d0264 | 2019-07-02 | 2019-07-02 |
| HASH | 1fd70d399d616bfac82a2d3ae69ec3f… | 2019-07-02 | 2019-07-02 |
| URL | https://www.calderonflooring.co… | 2019-07-02 | 2019-07-02 |
| URL | https://darvishkhan.net/wp-cont… | 2019-07-02 | 2019-07-02 |
| URL | https://www.calderonflooring.co… | 2019-07-02 | 2019-07-02 |