Analysis of Lazarus malware abusing Non-ActiveX Module in South Korea

2021-07-08 • S2W •

https://medium.com/s2wlab/analysis-of-lazarus-malware-abusing-non-activex-module-in-south-korea-7d52b9539c12

Thumbnail for Analysis of Lazarus malware abusing Non-ActiveX Module in South Korea

S2W analyzes a Lazarus-linked signed DLL disguised as the open-source Notepad++ ComparePlus plugin and apparently tailored to systems with a South Korean Non-ActiveX security component installed. The malware checked for INITECH/INISAFE Web EX Client files and SCSKAppLink.dll before loading itself through comp.exe, using DLL injection to force execution. Its final behavior was to download an additional payload from compromised Korean web infrastructure, decrypt it with RC5, and execute it in memory; observed URLs included grandgolf.co.kr, namchuncheon.co.kr, and kdone.co.kr paths with product_field=racket. The report ties the sample to Lazarus through similarities in string-decoding logic and the group's recurring use of normal-file masquerading, signed components, and domestic Korean distribution sites.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a881c9f40c1a5be3919cafb2ebe2bb5… 2021-07-08 2023-04-12
HASH 61367c3a1d4c9ccaee568157bc4cf2f… 2021-07-08 2021-07-08

Related Actors

Related Reports

« Back