LAZARUS’ FALSE FLAG MALWARE
2017-02-20 • Bae Systems •
http://baesystemsai.blogspot.kr/2017/02/lazarus-false-flag-malware.html
BAE Systems analyzed malware and watering-hole infrastructure tied to a wave of bank attacks that earlier reporting had linked to the Lazarus threat actor. The examined samples included an encrypted backdoor loaded by a DLL, decrypted with XOR and RC4 routines, then injected into a process and controlled through a custom binary protocol supporting file transfer and remote download commands. The attackers used compromised websites to redirect selected visitors to a profiling script that checked IP allowlists, browser details, operating system version, and plugins before serving Adobe Flash or Microsoft Silverlight exploits. Russian-language command strings in the bot appeared inconsistent with native Russian usage, leading the researchers to assess them as a likely decoy intended to spoof the malware’s origin. The report matters because it connects targeted financial-sector watering holes, exploit-kit filtering, Lazarus-linked loader behavior, and false-flag language artifacts into a defensible detection picture.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 8cad61422d032119219f465331308c5… | 2017-02-20 | 2020-08-26 |
| HASH | 6c1d8c4afbc7f85f05fb2e4d17e5553… | 2017-02-20 | 2017-04-03 |
| HASH | 8e32fccd70cec634d13795bcb1da85ff | 2017-02-20 | 2017-02-20 |
| HASH | 9216b29114fb6713ef228370cbfe4045 | 2017-02-20 | 2017-02-20 |
| HASH | 752b8e93a8f6803b265dd3a7cd39df8… | 2017-02-16 | 2017-02-20 |
| HASH | cd10ffb7a88f0d2ec69326e7a13f00b… | 2017-02-16 | 2017-02-20 |
| HASH | c1b29afcfddb79cfd57545b86009221… | 2017-02-12 | 2017-02-20 |