APT-C-26(Lazarus)组织利用WinRAR漏洞部署Blank Grabber木马的技术分析

2025-12-12 Qihoo360 Technical Analysis of APT-C-26 (Lazarus) Using a WinRAR Vulnerability to Deploy the Blank Grabber Trojan

https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&mid=2247507693&idx=1&sn=e73e1cca5af2ee80c3037daa1dbd2ab1

Thumbnail for APT-C-26(Lazarus)组织利用WinRAR漏洞部署Blank Grabber木马的技术分析

360 researchers attribute a malicious archive campaign to APT-C-26/Lazarus, reporting exploitation of WinRAR path traversal CVE-2025-8088 through a file named Pharos.rar. The archive is disguised as a Pharos Automation Bot project and abuses NTFS Alternate Data Stream handling to drop 1.bat into the Windows Startup folder when extracted. The infection chain displays a fake Windows Defender update warning, downloads and runs an obfuscated Python loader from Dropbox, installs Python if needed, adds persistence, and retrieves Tsunami Injector and additional payloads. The final Blank Grabber configuration steals Chromium and Firefox browser data, Discord and Telegram sessions, Wi-Fi credentials, gaming sessions, and seed or private-key material from more than 20 cryptocurrency wallets including MetaMask, Exodus, and Electrum. The cryptocurrency-themed lure and enabled theft functions make the campaign especially relevant to defenders tracking Lazarus operations against crypto users and developers.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 79c01d2c07859e1e208071173c02813… 2025-12-12 2025-12-12
HASH 99b5cc8bfbfcc388208e2f8ff22d631… 2025-12-12 2025-12-12
HASH 273af5e2e0130baee7d3b55081be5ad5 2025-12-12 2025-12-12

Related Actors

Related Reports

« Back