LAZARUS’ FALSE FLAG MALWARE

2017-02-20 • Bae Systems •

http://baesystemsai.blogspot.kr/2017/02/lazarus-false-flag-malware.html

Thumbnail for LAZARUS’ FALSE FLAG MALWARE

BAE Systems analyzed malware and watering-hole infrastructure tied to a wave of bank attacks that earlier reporting had linked to the Lazarus threat actor. The examined samples included an encrypted backdoor loaded by a DLL, decrypted with XOR and RC4 routines, then injected into a process and controlled through a custom binary protocol supporting file transfer and remote download commands. The attackers used compromised websites to redirect selected visitors to a profiling script that checked IP allowlists, browser details, operating system version, and plugins before serving Adobe Flash or Microsoft Silverlight exploits. Russian-language command strings in the bot appeared inconsistent with native Russian usage, leading the researchers to assess them as a likely decoy intended to spoof the malware’s origin. The report matters because it connects targeted financial-sector watering holes, exploit-kit filtering, Lazarus-linked loader behavior, and false-flag language artifacts into a defensible detection picture.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8cad61422d032119219f465331308c5… 2017-02-20 2020-08-26
HASH 6c1d8c4afbc7f85f05fb2e4d17e5553… 2017-02-20 2017-04-03
HASH 8e32fccd70cec634d13795bcb1da85ff 2017-02-20 2017-02-20
HASH 9216b29114fb6713ef228370cbfe4045 2017-02-20 2017-02-20
HASH 752b8e93a8f6803b265dd3a7cd39df8… 2017-02-16 2017-02-20
HASH cd10ffb7a88f0d2ec69326e7a13f00b… 2017-02-16 2017-02-20
HASH c1b29afcfddb79cfd57545b86009221… 2017-02-12 2017-02-20

Related Actors

Related Reports

« Back