Site navigation

Lazarus Group Targets Windows Internet Information Services

Michael Edgar

,

Lazarus Group Windows
A North Korean hacking group is targeting Windows Internet Information Services (IIS), allowing them to gain access to corporate networks.

The Lazarus Group, known as a North Korean state-sponsored hacking organisation by the FBI, is responsible for some of the costliest cyber attacks in history.

Analysts believe that the Lazarus Group’s activities partially funds North Korea’s weapons development programmes.

The cyber criminal enterprise is now targeting Windows IIS servers, and was uncovered by South Korean researchers at the AhnLab Security Emergency Response Center (ASEC).

IIS servers are used by many organisations to host apps, websites, and services. It has been available since the launch of Windows NT and supports HTTP, HTTPS, FTP, FTPS, SMTP, and NNTP protocols. Hacking groups can, however, make quick work of IIS servers that are poorly managed or outdated.

ASEC found that the Lazarus Group exploited vulnerabilities in the servers to execute malicious commands. They did this by using a dynamic link-library (DLL) side-loading technique, placing a malicious DLL in the same folder as a legitimate application and then executing the application which triggers the execution of the malicious DLL. 

The malicious DLL then decrypts an encoded portable executable (PE) file, executing it to memory. Afterwards, it clears the malicious DLL module and deletes itself. 

Once gaining access, the threat actor creates additional malware by exploiting the “colour picker plugin” for Notepad++. The malware then receives an encoded PE file to decrypt once again, and executes it in memory. 

After obtaining system credentials, the threat actor uses a remote access port to move laterally within the network. Up to date, no further malicious activity is detected. 

AhnLab suggests companies should proactively monitor abnormal process execution relationships and take pre-emptive measures, since the threat group primarily utilises the DLL side-loading technique during their initial infiltrations. Doing this will help prevent the threat group from carrying information exfiltration and lateral movement.


Recommended


Indicators of compromise are as follows: 

  • File Detection
    Trojan/Win.LazarLoader.C5427612 (2023.05.15.02)
    Trojan/Win.LazarLoader.C5427613 (2023.05.15.03)
  • DLL Side-loading File Path
    C:\ProgramData\USOShared\Wordconv.exe
    C:\ProgramData\USOShared\msvcr100.dll
  • MD5
    e501bb6762c14baafadbde8b0c04bbd6: diagn.dll
    228732b45ed1ca3cda2b2721f5f5667c: msvcr100.dll
    47d380dd587db977bf6458ec767fee3d: ? (Variant malware of msvcr100.dll)
    4d91cd34a9aae8f2d88e0f77e812cef7: cylvc.dll (Variant malware of msvcr100.dll)

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data