Rewterz Threat Alert – Hancitor InfoStealer – Active IOCs
October 6, 2021Rewterz Threat Advisory – CVE-2021-0703 – Google Android Vulnerability
October 6, 2021Rewterz Threat Alert – Hancitor InfoStealer – Active IOCs
October 6, 2021Rewterz Threat Advisory – CVE-2021-0703 – Google Android Vulnerability
October 6, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Profit and Loss Statement. zip and Profit and Loss Statement.xlsx.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region
Impact
- Exposure of Sensitive Data
- Credential Theft
- Information Theft and Espionage
Indicators of Compromise
MD5
- 173edf96e60b3fd520801a6c1adee7e0
- db315d7b0d9e8c9ca0aa6892202d498b
- a2be99a5aa26155e6e42a17fbe4fd54d
- 5bec2687fd743d23331cd54c987b44de
SHA-256
- de12a81e816c160167799b8b2febfdfec03845d0de454a308f9a1d122f28c4ee
- c31cbb849b8562a7c2801724c2a03369be7b459ff789c451e432844da5d47101
- 8afdf8513a6e3bede16187004daccc95e193a29062415d9ba0c29b98a5a927d1
- 6f28d7875dff596fb6f4c77c411186ccf6bb94b0c97e86061c81d039fcf3c113
SHA-1
- e04e59023079b4fbc75ebcb277d2cdbf4ba425ab
- 281a93970fca90a926caefaffd989f649931252f
- 61c6a74dc3c370e6b113f3a90aa07ac7f409d443
- 6d97bd7c7fadccfdde6973bb84fa8438b6b2fb9c
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.