#LazarLoader
Malware/Tool
2023-02-15 • 라자루스 그룹이 사용한 안티 포렌식 기법
LazarLoader is a Windows downloader used in Lazarus operations against South Korean web servers. In the reported incidents, attackers compromised IIS servers, installed ASP web shells and proxy-style C2 scripts, and also deployed LazarLoader and privilege-escalation tools. The observed downloader contained a hard-coded payload address, downloaded encrypted executable content, verified that the decrypted result was a PE file, and loaded it directly into memory. Payload decryption used the 16-byte key “Node.Js_NpmStart.” The surrounding infrastructure relayed malware traffic through a compromised first-stage server to a second-stage C2 server.
-
12
Tagged Reports
-
1
Unique Authors
-
755
Active Days