Threat Advisory

Lazarus Group Exploiting Aerospace and Defense Networks using Comebacker Backdoor

Threat: Malicious Campaign
Threat Actor Name: Lazarus Group
Threat Actor Type: State-Sponsored
Targeted Region: Global
Alias: Genie Spider, Labyrinth Chollima, UNC577, UNC2970, UNC4034, UNC4736, UNC4899, Zinc, DEV-0139, Diamond Sleet, Jade Sleet, TA404, ITG03, Hastati Group, Hidden Cobra, Black Alicanto, ATK 3, Dangerous Password,CryptoCore , Leery Turtle , CryptoMimic, Group 77, Whois Hacking Team, NewRomanic Cyber Army Team, Appleworm, APT-C-26, SectorA01, Guardians of Peace, Gods Apostles, Gods Disciples, TraderTraitor
Threat Actor Region: North Korea
Targeted Sector: Technology & IT, Government & Defense, Aerospace & Aviation
Criticality: High
[subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A targeted espionage campaign has been identified against aerospace and defense sector organizations, employing a newly observed variant of the Comebacker backdoor. The malicious actor uses themed lure documents impersonating high‑profile aviation and defense entities to initiate infection, indicating a deliberate and focused threat to strategic industry targets.[/subscribe_to_unlock_form]


EXECUTIVE SUMMARY:

A targeted espionage campaign has been identified against aerospace and defense sector organizations, employing a newly observed variant of the Comebacker backdoor. The malicious actor uses themed lure documents impersonating high‑profile aviation and defense entities to initiate infection, indicating a deliberate and focused threat to strategic industry targets.[emaillocker id="1283"]

The threat actor has deployed a newly observed variant of the Comebacker backdoor that begins with malicious Microsoft Word documents containing embedded VBA macros which rely on user execution to deliver a loader DLL and a decoy document themed around aerospace and defense topics; the loader uses the ChaCha20 stream cipher to decrypt and write a second stage loader that maps the final Comebacker payload into memory and invokes its entry point. Command and control is performed over HTTPS where the initial beacon uses a crafted URL query string and outbound data is encrypted with AES 128 CBC then Base64 encoded; server responses can instruct the malware to sleep, terminate, or download and execute additional payloads, with supplementary payloads verified by MD5, decrypted with ChaCha20, and loaded into memory to evade disk-based detection. The campaign leverages infrastructure such as open directory listing sites and multiple command and control domains discovered through pivoting and uses highly tailored lure documents that impersonate prominent aerospace and defense organizations to support a focused spear phishing approach.

It reflects the advanced capabilities of the threat actor, with custom loaders, in-memory execution, encrypted communications, tailored lures, and infrastructure pivoting all indicating long-term targeted espionage rather than opportunistic mass malware. Organizations in the aerospace, defense, and affiliated research sectors should assume they are potential targets, reinforce their macro and malware defenses, apply network detection for anomalous command-and-control traffic, and verify their endpoint resilience against multi-stage in-memory.

 

Tactic Technique Id Technique Sub-technique
Resource Development T1583.001 Acquire Infrastructure Domains
Initial Access T1566.001 Phishing Spearphishing Attachment
Execution T1204.002 User Execution Malicious File
T1204.005 Malicious Library
T1059.001 Command and Scripting Interpreter PowerShell
T1059.003 Windows Command Shell
T1059.005 Visual Basic
Persistence T1547.001 Boot or Logon Autostart Execution Registry Run Keys / Startup Folder
T1547.009 Shortcut Modification
Defense Evasion T1140 Deobfuscate / Decode Files or Information
T1027.013 Obfuscated Files or Information Encrypted / Encoded File
T1027.015 Obfuscated Files or Information Compression
T1218.011 System Binary Proxy Execution Rundll32
T1620 Reflective Code Loading
Command and Control T1132.001 Data Encoding Standard Encoding

 

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu