Lazarus故技重施,dream job行动再次上演
2022-06-02 • CN-SEC • Lazarus repeats his old tricks and the dream job operation is staged again •
Anheng CERT attributed a renewed Dream Job-style operation to Lazarus after observing Binance developer recruitment lures aimed at job seekers, with the suspected objective of cryptocurrency theft. The delivery chain used password-protected PDF decoys alongside a fake Password.txt LNK file that launched obfuscated PowerShell and mshta to retrieve remote HTA code. Later stages decrypted AES/Gzip-packed PowerShell, attempted UAC bypass, added Windows Defender exclusions, and downloaded Cobalt Strike via gdk.exe and jdk.exe. The activity matters because it shows Lazarus reusing social-engineering patterns against cryptocurrency targets while changing obfuscation and evasion details; reported infrastructure included crypto.blockchaincapital[.]space, mira.itb.ac[.]id, filebin[.]net, and Cobalt Strike callback 174.038.24[.]107:80.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b9899082824f1273e53cbf1d455f360… | 2022-06-02 | 2022-06-22 |
| HASH | 8e3af0de5123ee39c3ff4d2d880e01a… | 2022-06-02 | 2022-06-02 |
| HASH | cce4754506394f6513b23facb22f556… | 2022-06-02 | 2022-06-02 |
| HASH | 92b3a0ff92495b12cce7209a2ebb2b3… | 2022-06-02 | 2022-06-02 |
| URL | https://crypto.blockchaincapita… | 2022-06-02 | 2022-06-02 |
| URL | https://mira.itb.ac.id/jdk.hta | 2022-06-02 | 2022-06-02 |
| URL | https://crypto.blockchaincapita… | 2022-06-02 | 2022-06-02 |
| URL | https://crypto.blockchaincapita… | 2022-06-02 | 2022-06-02 |
| URL | https://filebin.net/wc3oofuc28p… | 2022-06-02 | 2022-06-02 |
| DOMAIN | crypto.blockchaincapital.space | 2022-06-02 | 2022-06-02 |
| DOMAIN | mira.itb.ac.id | 2022-06-02 | 2022-06-02 |
| HASH | 562abb0f0dbfa0fb6a31c7819dc5709… | 2022-06-02 | 2022-06-02 |
| HASH | 7de9c291075c9b9723c80b3715858ec… | 2022-06-02 | 2022-06-02 |
| HASH | f12f9f12bbe887fb6a250dd9903cee6… | 2022-06-02 | 2022-06-02 |