Rewterz Threat Alert – APT21 aka BlackTech Targeting East Asian Countries
December 1, 2021Rewterz Threat Alert – SideWinder APT Group – Active IOCs
December 1, 2021Rewterz Threat Alert – APT21 aka BlackTech Targeting East Asian Countries
December 1, 2021Rewterz Threat Alert – SideWinder APT Group – Active IOCs
December 1, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Month_end PnL Statement. zip, and Month_end PnL Statement.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.
Impact
- Information theft and espionage
- Exposure of sensitive data
Indicators of Compromise
Filename
- Month_end PnL Statement[.] zip
- Month_end PnL Statement[.]lnk
IP
- 152[.]89[.]247[.]236
MD5
- 69c9881a6b7b89a648074328292da7e8
- 84dd7ccb69d0010c97c1fc336650d5e2
SHA-256
- f58ff04914a063c6bede1738339ba64dd8ef2cdb88214c6fc8d98cb6c4bd2539
- 52e9361cfec3bc643f5ac715709e1818766e1790c7f83e93e3ee7cc96fd1a473
SHA-1
- 02140fdbd963368d09955035d65e853beb65ecd3
- 2cd776c976b89dc5551c7d5b5817f708528c9560
URL
- http[:]//152[.]89[.]247[.]236/ss
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.