Lazarus Group Uses the DLL Side-Loading Technique (2)
ID: bbd588f4-d6c9-5cb9-b8a4-eea20803d7f0
STIX ID: report--bbd588f4-d6c9-5cb9-b8a4-eea20803d7f0
Feed Name: ASEC
AhnLab ASEC reports that the Lazarus Group is leveraging DLL side-loading via a legitimate wmiapsrv.exe to load malicious wbemcomn.dll and netutils.dll backdoors; wbemcomn.dll uses a GetSystemFirmwareTable-based verification routine to ensure execution only on specific targets, while netutils.dll loads a payload directly (e.g., C:\ProgramData\Microsoft Editor\editor.dat). The report includes detection names and MD5 indicators for the discovered samples and notes Lazarus’ use of spear phishing and supply-chain tactics.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
