#LazarLoader
Malware/Tool
2022-10-06 • 라자루스 그룹 DLL Side-Loading 기법 이용 (mi.dll)
LazarLoader is a Windows downloader used in Lazarus operations against South Korean web servers. In the reported incidents, attackers compromised IIS servers, installed ASP web shells and proxy-style C2 scripts, and also deployed LazarLoader and privilege-escalation tools. The observed downloader contained a hard-coded payload address, downloaded encrypted executable content, verified that the decrypted result was a PE file, and loaded it directly into memory. Payload decryption used the 16-byte key “Node.Js_NpmStart.” The surrounding infrastructure relayed malware traffic through a compromised first-stage server to a second-stage C2 server.
-
13
Tagged Reports
-
1
Unique Authors
-
887
Active Days