Rewterz
Rewterz Threat Advisory – CVE-2019-19492 – ICS: Sensormatic Electronics victor
October 29, 2021
Rewterz
Rewterz Threat Alert – APT SideWinder Group – Active IOCs
October 29, 2021

Rewterz Threat Alert – Lazarus APT Group – Active IOCs

Severity

High

Analysis Summary

Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Profit and Loss Statement. zip and Profit and Loss Statement.xlsx.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region

Impact

  • Exposure of Sensitive Data
  • Information Theft and Espionage

Indicators of Compromise

Filename

  • FiCas AG Job Description[.]lnk

MD5

  • 3c324706e3bae0b7187b134a813011cb

SHA-256

  • 38ed248501bd35cd140f8376ac42e2c5a46ed4ec71cff0cec290fbc93678f323

SHA-1

  • ed94bef7f2d99ee150bf38d263a902586672c7d8

URL

  • https[:]//note[.]onedocshare[.]com/seZlG2VYJ6l05Yn4tvYj93t9eK3OX72pIMiW95JlhDY=om/seZlG2VYJ6l05Yn4tvYj93t9eK3OX72pIMiW95JlhDY=

Remediation

  • Always be suspicious about emails sent by unknown senders.
  • Never click on links/attachments sent by unknown senders.
  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.