

Rewterz Threat Alert – Donot APT Group – Active IOCs
January 25, 2022
Rewterz Threat Advisory – Multiple Util-Linux Libmount Vulnerabilities
January 25, 2022
Rewterz Threat Alert – Donot APT Group – Active IOCs
January 25, 2022
Rewterz Threat Advisory – Multiple Util-Linux Libmount Vulnerabilities
January 25, 2022Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Month_end PnL Statement. zip, and Month_end PnL Statement.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.

Impact
- Information theft and espionage
- Exposure of sensitive data
Indicators of Compromise
Domain Name
- portal[.]gfinanzen[.]net
Filename
- RFP_AllianxMexico_2022[.]doc
MD5
- b371e1c2ca2e5718e151760bc4664366
SHA-256
- 3542078fd524e3cb141d5bebf96aea73467505a07ae72fc58395afa14f22e8a3
SHA-1
- 73457d23e5235df0fcfbf6547aaf26cccc765011
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.