Summary:
The Lazarus group Attacks are being carried out targeting Windows IIS web servers. The group with broad assistance in the country. Threat actors typically leverage the vulnerability appropriate for the vulnerable version they discover during a scan to install a web shell or run malicious commands on the web server.[/subscribe_to_unlock_form]
Summary:
The Lazarus group Attacks are being carried out targeting Windows IIS web servers. The group with broad assistance in the country. Threat actors typically leverage the vulnerability appropriate for the vulnerable version they discover during a scan to install a web shell or run malicious commands on the web server.[emaillocker id="1283"]
The Windows IIS web server process w3wp.exe, the threat actor installs a malicious DLL (msvcr100.dll) in the same folder path as a legitimate program (Wordconv.exe). After that, they run the legitimate application to start the malicious DLL from scratch. This attack strategy is referred to as the DLL side-loading technique. After It has been repeatedly established that the Lazarus organization uses the DLL side-loading approach to launch malware. The regular process used in the DLL side-loading performance has a name that the organization threat actor has been continuously modifying. Similar to DLL search-order hijacking, DLL side-loading describes the proxy execution of a malicious DLL via an appropriate binary hidden in the same directory. The executing PE file within the memory space, the “msvcr100.dll” and “cylvc.dll” use the “Salsa20” method to decrypt the data files with the .dat extension. A backdoor that connected to the threat actor's C&C server was part of the PE that was run inside the memory space. The attack on the chain also included the use of Quick Colour Picker, a defunct open-source Notepad++ plugin, to spread more malware and enable lateral movement and credential theft.
The Lazarus group used several of attack vectors, including Log4Shell, a public certificate vulnerability, a 3CX supply chain attack, etc. One of the most dangerous gangs that are currently carrying out attacks worldwide is this one. Therefore, corporate security managers should use attack surface management to identify the assets that can be vulnerable to threat actors and exercise prudence by always using the latest security fixes.
Threat Profile:

References:
The following reports contain further technical details:
https://thehackernews.com/2023/05/n-korean-lazarus-group-targets.html
[/emaillocker]