Lazarus on the hunt for big game
2020-07-28 • Kaspersky •
https://securelist.com/lazarus-on-the-hunt-for-big-game/97757/
Kaspersky linked VHD ransomware operations to Lazarus after incident-response evidence showed a MATA framework backdoor in the same victim environment and no sign of another actor during the intrusion. One European incident used a victim-specific spreading utility with administrative credentials and IP addresses to brute-force SMB, copy the ransomware, and execute it through WMI. A later case likely began with opportunistic VPN exploitation, privilege escalation, a backdoor deployment, Active Directory takeover, and network-wide VHD staging through a Python downloader within about 10 hours. The ransomware used AES-256 in ECB mode and RSA-2048, while the report lists MATA command-and-control infrastructure and VHD hashes, making the activity notable as a Lazarus-run targeted ransomware operation rather than a typical outsourced cybercrime ecosystem case.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 104.232.71.7 | 2020-07-22 | 2021-03-23 |
| IPv4 | 172.93.184.62 | 2020-07-22 | 2021-03-23 |
| IPv4 | 23.227.199.69 | 2020-07-22 | 2021-03-23 |
| HASH | 73a10be31832c9f1cbbd79859041100… | 2020-07-28 | 2020-07-28 |
| HASH | 5e78475d10418c6938723f6cfefb89d… | 2020-07-28 | 2020-07-28 |
| HASH | 097ca829e051a4877bca093cee34018… | 2020-07-28 | 2020-07-28 |
| HASH | 6cb9afff8166976bd62bb29b12ed617… | 2020-07-28 | 2020-07-28 |
| HASH | 52888b5f881f4941ae7a8f4d84de27f… | 2020-07-28 | 2020-07-28 |
| DOMAIN | mnmski.cafe24.com | 2020-07-28 | 2020-07-28 |