The Lazarus Group, known as a North Korean state-sponsored hacking organisation by the FBI, is responsible for some of the costliest cyber attacks in history.
Analysts believe that the Lazarus Group’s activities partially funds North Korea’s weapons development programmes.
The cyber criminal enterprise is now targeting Windows IIS servers, and was uncovered by South Korean researchers at the AhnLab Security Emergency Response Center (ASEC).
IIS servers are used by many organisations to host apps, websites, and services. It has been available since the launch of Windows NT and supports HTTP, HTTPS, FTP, FTPS, SMTP, and NNTP protocols. Hacking groups can, however, make quick work of IIS servers that are poorly managed or outdated.
ASEC found that the Lazarus Group exploited vulnerabilities in the servers to execute malicious commands. They did this by using a dynamic link-library (DLL) side-loading technique, placing a malicious DLL in the same folder as a legitimate application and then executing the application which triggers the execution of the malicious DLL.
The malicious DLL then decrypts an encoded portable executable (PE) file, executing it to memory. Afterwards, it clears the malicious DLL module and deletes itself.
Once gaining access, the threat actor creates additional malware by exploiting the “colour picker plugin” for Notepad++. The malware then receives an encoded PE file to decrypt once again, and executes it in memory.
After obtaining system credentials, the threat actor uses a remote access port to move laterally within the network. Up to date, no further malicious activity is detected.
AhnLab suggests companies should proactively monitor abnormal process execution relationships and take pre-emptive measures, since the threat group primarily utilises the DLL side-loading technique during their initial infiltrations. Doing this will help prevent the threat group from carrying information exfiltration and lateral movement.
Recommended
- Extinction by AI? Statement of AI Risks Signed by Experts
- Heriot-Watt: What’s the Impact of Digitisation On Young People?
- New Partnership Gives Ethical Hackers Practical Experience
Indicators of compromise are as follows:
- File Detection
Trojan/Win.LazarLoader.C5427612 (2023.05.15.02)
Trojan/Win.LazarLoader.C5427613 (2023.05.15.03) - DLL Side-loading File Path
C:\ProgramData\USOShared\Wordconv.exe
C:\ProgramData\USOShared\msvcr100.dll - MD5
e501bb6762c14baafadbde8b0c04bbd6: diagn.dll
228732b45ed1ca3cda2b2721f5f5667c: msvcr100.dll
47d380dd587db977bf6458ec767fee3d: ? (Variant malware of msvcr100.dll)
4d91cd34a9aae8f2d88e0f77e812cef7: cylvc.dll (Variant malware of msvcr100.dll)





