Rewterz Threat Advisory – 84,000 Websites Impacted by High-Severity WordPress Flaw
January 19, 2022Rewterz Threat Alert – Mirai Botnet – Active IOCs
January 19, 2022Rewterz Threat Advisory – 84,000 Websites Impacted by High-Severity WordPress Flaw
January 19, 2022Rewterz Threat Alert – Mirai Botnet – Active IOCs
January 19, 2022Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Lockheed_Martin_JobOpportunities.docx. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.
Impact
- Information theft and espionage
- Exposure of sensitive data
Indicators of Compromise
Domain Name
- lm-career[.]com
Filename
Lockheed_Martin_JobOpportunities[.]docx
MD5
- 3f326da2affb0f7f2a4c5c95ffc660cc
SHA-256
- 0d01b24f7666f9bccf0f16ea97e41e0bc26f4c49cdfb7a4dabcc0a494b44ec9b
SHA-1
- f38abb67d47a4f69536ae67aa9c6df7287c08869
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.