Analysis of THREATNEEDLE C&C Communication (feat. Google TAG Warning to Researchers)
2021-01-27 • S2W •
Malware mentioned in “North Korean hackers have targeted security researchers via social media report” published by Google Threat Analysis Group (TAG) is considered to be a ThreatNeedle which is dubbed by Kaspersky. In addition, the malware and C2 communication have in common with Operation MalBus. We already disclosed the deep analysis regarding C2 communication of ThreatNeedle at DCC 2019 and Kaspersky SAS Lightning Talk 2019. ThreatNeedle is already known that it has been used by the Lazarus group along with Manuscrypt from the past.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 07375a711dda055cfb8777d31aff9cf… | 2021-01-27 | 2021-01-27 |
| HASH | 011cc019872f75c30cfa1d41201fc23… | 2021-01-27 | 2021-01-27 |
| HASH | 3fd610f69ef1808431b090c40a06562… | 2021-01-27 | 2021-01-27 |
| HASH | 46196370d2cd24b19bd1272a9c3632e… | 2021-01-27 | 2021-01-27 |
| HASH | 9f5e407601032063e1f1d263e9a2b11… | 2021-01-27 | 2021-01-27 |
| HASH | e0a62ba2c58b1a8e9484f1c4452aaaf… | 2021-01-27 | 2021-01-27 |
| HASH | 1a327cced0b0c0bf99146f276fb7a93… | 2021-01-27 | 2021-01-27 |
| HASH | cd4658151e41749ec71fe64d9e88b35… | 2021-01-27 | 2021-01-27 |
Related Actors
Related Reports
Shares tags: DreamJob, ThreatNeedle, Lazarus • Same author: S2W
2021-02-25 •
66% Match
#NukeSped
#ThreatNeedle
#Manuscrypt
#Lazarus
#T1082
#T1059.003
#T1140
#T1070.004
#T1041
#T1071.001
#T1112
#T1083
#T1204.002
#T1566.002
#T1057
#T1547.001
#T1135
#T1070.002
#T1049
#T1132.002
#T1016
#T1036.004
#T1090.001
#T1036.003
#T1560.001
#T1021.002
#T1033
#T1569.002
#T1543.003
#T1104
#T1557.001
#T1070.003
#T1007
#T1572
#Responder
Shares tags: ThreatNeedle, Lazarus • Published within a month
Shares tags: ThreatNeedle, Lazarus • Published within a month
Shares tags: DreamJob, Lazarus • Published within a week
Shares tags: DreamJob, Lazarus • Published within a week
Shares tags: DreamJob, Lazarus • Published within a week