Rewterz Threat Alert – SNAKE Ransomware – Active IOCs
December 3, 2021Rewterz Threat Alert – Quasar RAT – Active IOCs
December 3, 2021Rewterz Threat Alert – SNAKE Ransomware – Active IOCs
December 3, 2021Rewterz Threat Alert – Quasar RAT – Active IOCs
December 3, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name idahelper.dll. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region
Impact
- Information theft and espionage
- Exposure of sensitive data
Indicators of Compromise
Filename
- Goldman Sachs Job Opportunities[.]rar
MD5
- 378abca93a29fd939507dad6634f9605
SHA-256
- 6d72df200fbd8b8220921c4163fd7151d8cfb38c3b433252130ea9c50fef454d
SHA-1
- dcd60583cc7bbb5acaacfa4d2e4f96eacd397955
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.