A Cascade of Compromise: Unveiling Lazarus' New Campaign
Cyber Security Threat Summary:
Earlier this year, a software vendor fell victim to a Lazarus malware attack due to unpatched legitimate software. Despite previous warnings and patches from the vendor, vulnerabilities remained, allowing the threat actor to exploit them. Fortunately, proactive measures detected and thwarted an attack on another vendor. Further investigation revealed that the software vendor had been repeatedly targeted by Lazarus, indicating a persistent and determined threat actor likely seeking valuable source code or tampering with the software supply chain. The adversary used advanced techniques and introduced the SIGNBT malware for victim control.
The SIGNBT malware is loaded in memory, and it communicates with the command and control (C2) server using distinctive prefixes. It can execute various commands on the victim's system and has an extensive set of functionalities. In addition to SIGNBT, Lazarus employed the LPEClient malware, which collects victim information and downloads additional payloads to run in memory. This malware has evolved over time to avoid detection. Lazarus has been involved in multiple campaigns in 2023, targeting different sectors with varying objectives, but consistently using LPEClient as the initial infection vector.
Suggested Correction(s):
The Lazarus group remains a highly active and versatile threat actor in today’s cybersecurity landscape. The threat actor has demonstrated a profound understanding of IT environments, refining their tactics to include exploiting vulnerabilities in high-profile software. This approach allows them to efficiently spread their malware once initial infections are achieved. Moreover, the activities of this notorious actor transcend geographic boundaries and industry sectors. They have targeted various industries, each with distinct objectives and using different tools, tactics and techniques. This underscores their recent and ongoing activity characterized by sophisticated methods and unwavering motivations.
Suggested Correction(s):
Organizations can make APT/Nation-State groups’ lives more difficult. Here’s how:
Link(s):
https://securelist.com/unveiling-lazarus-new-campaign/110888/