Rewterz Threat Alert – Amadey Botnet – Active IOCs
November 2, 2021Rewterz Threat Advisory – Multiple IBM InfoSphere Information Server
November 3, 2021Rewterz Threat Alert – Amadey Botnet – Active IOCs
November 2, 2021Rewterz Threat Advisory – Multiple IBM InfoSphere Information Server
November 3, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Boeing BDS MSE.docx. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region
Impact
- Information Theft and Espionage
- Exposure of Sensitive Data
Indicators of Compromise
Filename
- Boeing BDS MSE[.]docx
MD5
- 606695bae4f0eb5ba0f35b8897b9f57a
SHA-256
- 65b5709f67bb0fac31ec977f98cda6f89f4b38703ee5aeef0b633c33669ea88a
SHA-1
- 749f24447e2f724a54fcee18d8276695c8f2aa8c
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.