

Rewterz Threat Advisory –CVE-2021-34865 – NETGEAR Multiple Routers Authentication Bypass Security Vulnerability
August 31, 2021
Rewterz Threat Advisory – Multiple Node.js Security Vulnerabilities
September 1, 2021
Rewterz Threat Advisory –CVE-2021-34865 – NETGEAR Multiple Routers Authentication Bypass Security Vulnerability
August 31, 2021
Rewterz Threat Advisory – Multiple Node.js Security Vulnerabilities
September 1, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name JP Morgan Chase Job Opportunities.pdf.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.

Impact
- Exposure of Sensitive Data
- Credential Theft
- Information Theft and Espionage
Indicators of Compromise
Filename
- JP Morgan Chase Job Opportunities[.]pdf[.]lnk
MD5
- aefa2caddfeb3bccb1e696cc2cd6955a
SHA-256
- 0f73d0269cf77c53a38fb5863258755e3055979a6343d15573ab2222ce75f49b
SHA1
- c134e70eb8fa965976841ab914017a26dd140310
URL
- hxxP[:]//www[.]googlesheetpage[.]org/2
- hxxP[:]//www[.]googlesheetpage[.]org/1
- hxxps[:]//www[.]googlesheetpage[.]org/bSQphSxgStENEhz5Y+PZCpjr/NBSWGWjjhkJi/PvaqE=
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.