Rewterz
Rewterz Threat Alert – APT SideWinder Group – IOCs
December 9, 2021
Rewterz
Rewterz Threat Alert – APT MustangPanda – Active IOCs
December 9, 2021

Rewterz Threat Alert – Lazarus APT Group – Active IOCs

Severity

High

Analysis Summary

Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Month_end PnL Statement. zip, and Month_end PnL Statement.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.

Impact

  • Information theft and espionage
  • Exposure of sensitive data

Indicators of Compromise

Filename

  • LMCO – JD[.]doc

MD5

  • a145fc533ba903209544597c978d0e08
  • 4750356c638d963f1021103bebaafc55

SHA-256

  • ef2d3e488b781a7c6144afa8fc8ba2b6d085ca671100d04686097f3b4dd2ed42
  • 1fe9913962185ec1a915dc3a5923ad596cc28ff12ba6f7cacc0554c64ae7060f

SHA-1

  • b5d7d401d911ca776144637e13ffbce15227a2cf
  • 3af1ea283931bcf48c7ccc1f6e7ac5ca276b1ccf

Remediation

  • Always be suspicious about emails sent by unknown senders.
  • Never click on links/attachments sent by unknown senders.
  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.