Lazarus KillDisks Central American casino

2018-04-03 • ESET •

https://www.welivesecurity.com/2018/04/03/lazarus-killdisk-central-american-casino/

Thumbnail for Lazarus KillDisks Central American casino

ESET attributes attacks against a Central American online casino and other late-2017 targets to Lazarus based on overlapping toolsets, telemetry, Lazarus-linked malware, and shared static characteristics. The intrusions used Windows service-oriented NukeSped backdoors, a session-hijacking tool, credential theft utilities including a modified Mimikatz, remote access tooling, and destructive Win32/KillDisk.NBO variants deployed across more than 100 machines in the casino network. The KillDisk samples damaged systems by wiping or corrupting data and were closely related to variants seen against Latin American financial organizations. The report highlights how Lazarus combined custom malware, commercial protectors such as VMProtect, public tools, and destructive payloads in a complex multi-stage operation likely intended for cover-up, extortion, or sabotage.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8b6887c5ec6fadaefee78f089e9a347… 2018-04-03 2021-05-24
HASH c4a07bfc37a44dc85df2c63f369abb5… 2018-04-03 2020-03-09
HASH 25a91827265a5090928292186a0b3b5… 2018-04-03 2018-04-03
HASH 18ea298684308e50e3ae6bb66d7321a… 2018-04-03 2018-04-03
HASH d39311c74deb60c736982c1ab74d668… 2018-04-03 2018-04-03
HASH 7c55572e8573d08f3a69fb15b7fef10… 2018-04-03 2018-04-03
HASH e7fdeab60aa4203ea0ff24506b3fc66… 2018-04-03 2018-04-03
HASH 91dfd9ef7d61ef1c1c20bf0dd29fd0e… 2018-04-03 2018-04-03
HASH 8826d4edbb00f0a45c23567b16beed2… 2018-04-03 2018-04-03
HASH 1750d7ae9fccf192a79386a589e2f90… 2018-04-03 2018-04-03

Related Actors

Related Reports

« Back