Analysis of Lazarus Group’s Attack on Windows Web Servers
ID: 238fb1ac-5ff5-5b5f-9f6e-b4181bfcf63b
STIX ID: report--238fb1ac-5ff5-5b5f-9f6e-b4181bfcf63b
Feed Name: ASEC
ASEC observed the Lazarus APT compromising South Korean IIS web servers to install encoded ASP web shells and a first-stage C2 proxy (supporting form and cookie modes), deploy LazarLoader (a memory-loading downloader using a hard-coded decryption key) and a UACMe-based privilege escalation component to execute a backdoor with elevated privileges; the report includes command mappings, web shell functionality, decryption strings, example execution logs, file names and MD5 hashes, and recommended mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
