Mandiant security researchers have recently identified a group of hackers which is believed to be from North Korea is actively seeking security researchers and media outlets with fake job proposals in the following regions:-
As a result, three different families of malware are deployed into the target’s environment. Using social engineering techniques, the threat actors persuade their targets to engage in a WhatsApp conversation with them.
In order to establish a foothold within the target’s corporate environment, a C++ malware payload called “PlankWalk” is dropped through this channel.
Mandiant has been tracking the particular campaign since June 2022, the observed activity overlaps with “Operation Dream Job,” attributed to the North Korean cluster known as the “Lazarus group.”
In June 2022, the Mandiant team began to monitor the campaign on a continuous basis, and all these activities have been ongoing since then.
A North Korean cluster named Lazarus group has been attributed to this activity, which overlaps with “Operation Dream Job.”
While this campaign was associated with a separate group, Mandiant tracked the cluster as “UNC2970” since they observed significant differences in:-
In addition, the attackers have used previously unknown malware known as:-
Previous targets of this group have been tech companies, media companies, and defense-related entities.
It is believed that the hackers began their attack by posing as job recruiters and approaching targets through LinkedIn.
The recruitment process was ultimately conducted through WhatsApp, where they sent a Word document that contained malicious macros in order to proceed further.
Some of the Word documents are altered to match the job descriptions they are promoting to their target audiences in an effort to make them look more professional.
Remote template injection is performed by the macros in the Word document. Using the compromised WordPress websites as a C&C (command and control center), the attacker downloads a TightVNC’s malicious version and this is done via remote template injection.
As part of Mandiant’s tracking system, this customized version of TightVNC is referred to as LidShift. An encrypted DLL will be loaded into the system’s memory via reflective DLL injection as soon as the program has been executed.
As a result of loading this file, the compromised system will be enumerated by a malware downloader named LidShot. This malware downloader will then deploy a malware boot loader that will establish a foothold on the device that is compromised.
A new, custom malware dropper is used by North Korean hackers during the post-exploitation phase of the attack, and it is known as “TouchShift.” While the TouchShift is designed to mimic the behavior of a legitimate Windows binary in order to carry out the attack.
There are then a number of illicit tools that TouchShift loads, including:-
There are 49 commands available in the new custom backdoor SideShow, which is the most interesting of the bunch. It is possible for an attacker to perform the following actions on the compromised system using these commands:-
Moreover, using the PowerShell scripts, threat actors have been also tracked deploying the “CloudBurst” malware to target organizations without VPNs.
Additionally, this tool masquerades itself as a legitimate Windows file, namely “mscoree.dll,” and has the function of enumerating the system.
The Mandiant’s analysts discovered suspicious drivers in the log files of compromised systems, as well as an unusual DLL file (“_SB_SMBUS_SDK.dll”) when analyzing the logs.
An in-memory dropper known as LightShift had created these files, in response to another file that had been named “Share.DAT.”
There are multiple payloads loaded into the dropper from which it is possible to read and write arbitrary information from the kernel memory as long as the dropper loads an obfuscated payload named “LightShow.”
As a result of the payload’s function, the intruder is able to evade detection and exploit the EDR’s kernel routines. By creating fake social media profiles that resembled vulnerability researchers, North Korean hackers previously targeted security researchers involved in vulnerability research.
Here below we have mentioned all the recommendations:-
Network Security Checklist – Download Free E-Book
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…