North Korea Turns Against New Targets?!

2019-02-19 • Checkpoint •

https://research.checkpoint.com/north-korea-turns-against-russian-targets/

Thumbnail for North Korea Turns Against New Targets?!

Check Point observed malicious Office documents uploaded from Russian sources that appeared tailored to Russian organizations and showed intrinsic connections to Lazarus tactics, techniques, and tools, while noting attribution limits. The infection chain used a ZIP containing a benign PDF decoy and a macro-enabled Word document; macros either downloaded a VBS stage from Dropbox-like infrastructure or later skipped directly to downloading the final payload. The VBS stage retrieved a CAB disguised as a JPEG from a compromised Iraqi server and expanded it with Windows expand.exe into the KEYMARBLE Lazarus backdoor. The activity was notable because it suggested North Korea-linked operators targeting Russian entities, an unusual victim set compared with the group’s better-known South Korean, U.S., Japanese, financial, and cryptocurrency operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 49a23160ba2af4fba01865127834829… 2019-02-19 2019-02-19
HASH 9894f6993cae186981ecb034899353a… 2019-02-19 2019-02-19
HASH f4bdf0f967330f9704b01cc962137a7… 2019-02-19 2019-02-19
IPv4 194.45.8.41 2019-02-19 2019-02-19
IPv4 37.238.135.70 2019-02-19 2019-02-19

Related Actors

Related Reports

« Back