Rewterz Threat Advisory – Multiple SAP Vulnerabilities
December 15, 2021Rewterz Threat Advisory – Microsoft Patches Multiple Security Vulnerabilities in Latest Patch Tuesday
December 15, 2021Rewterz Threat Advisory – Multiple SAP Vulnerabilities
December 15, 2021Rewterz Threat Advisory – Microsoft Patches Multiple Security Vulnerabilities in Latest Patch Tuesday
December 15, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Month_end PnL Statement. zip, and Month_end PnL Statement.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.
Impact
- Information theft and espionage
- Exposure of sensitive data
Indicators of Compromise
Filename
- LMCO – Material & Process Engineer[.]doc
MD5
- 34328e4c7b19a1d946426e6d3abf978f
SHA-256
- cae38f109d2f49c3bd763cf85495e967ae8c09d093088bd971d38d79238ca712
SHA-1
- 552cc4ae5804adf2454d98d1d0525a8da19541c9
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.