Lazarus APT组织使用西方某航空巨头招聘等信息针对特定国家的定向攻击事件分析

2020-04-30 • Qianxin • Analysis of targeted attacks against specific countries by the Lazarus APT organization using recruitment information from a Western aviation giant •

https://ti.qianxin.com/blog/articles/analysis-of-lazarus-apt-oriented-attack-event/

Thumbnail for Lazarus APT组织使用西方某航空巨头招聘等信息针对特定国家的定向攻击事件分析

QiAnXin reported a Lazarus-attributed targeted campaign using diplomatic-relations themes and Western aerospace recruitment lures, including Boeing-themed documents, to attack specific countries. The samples used remote template injection to fetch macro-enabled DOTM documents, helping evade antivirus detection before macros decoded embedded data and dropped 32-bit or 64-bit DLL payloads. The DLLs deleted the original document, established persistence with a startup-folder LNK, collected host and user information, and contacted C2 for follow-on execution, though the final malware was not recovered. QiAnXin linked the activity to Lazarus through similarities with previously reported Telsy activity, matching macro flow, DLL logic, and backdoor behavior.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b76b6bbda8703fa801898f843692ec1… 2020-04-30 2023-04-12
HASH 48b8486979973656a15ca902b7bb973… 2020-04-30 2023-04-12
HASH 34b4546e3468238702df24794e598ad… 2020-04-30 2023-04-12
HASH a3eca35d14b0e020444186a5faaba59… 2020-04-30 2023-04-12
HASH 1b0c82e71a53300c969da61b085c8ce… 2020-04-30 2023-04-12
HASH 1076b25d5fa5cccdddcaf3f788789ae… 2020-04-30 2023-04-12
HASH bff4d04caeaf8472283906765df3442… 2020-04-30 2023-04-12
HASH 37a3c01bb5eaf7ecbcfbfde1aab8489… 2020-04-30 2023-04-12
URL https://od.lk/d/MzBfMjA1Njc0ODd… 2020-04-30 2020-07-29
URL https://www.sanlorenzoyacht.com… 2020-04-30 2020-07-29
URL https://www.elite4print.com/adm… 2020-04-30 2020-04-30

Related Actors

Related Reports

« Back