Rewterz Threat Alert – Donot APT Group – IOCs
July 21, 2021Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
July 21, 2021Rewterz Threat Alert – Donot APT Group – IOCs
July 21, 2021Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
July 21, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.
Impact
- Credential theft
- Exposure of sensitive data
- Information theft and Espionage
Indicators of Compromise
Filename
- Tani_Khan_Matrimonial_biodata_for_email_circulation[.]docx
MD5
- bcb4a8f190f2124be57496649078e0ae
SHA-256
- df921413ee769ff2ad5476498aab7f443580c866bb787e9eac42fb7e90a0d4d6
SHA-1
- 5f8dacb771b4affa13a0125b55a7f817597e46a4
URL
- https[:]//page[.]googledocpage[.]com/05UFKsHKiaeEIeE056+xGehUOzj8wpfD7m7hoxqbbIo=
- https[:]//bit[.]ly/35FlWc2(hxxps[:]//page[.]googledocpage[.]com/WiU+Q6cgIESl8BPJ/swFnyqX1uFiFiTyQY6yZbnIMwc=)
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.