Rewterz Threat Alert – Gamaredon APT – Active IOCs
September 1, 2021Rewterz Threat Alert – Vidar Malware – Active IOCs
September 1, 2021Rewterz Threat Alert – Gamaredon APT – Active IOCs
September 1, 2021Rewterz Threat Alert – Vidar Malware – Active IOCs
September 1, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name SALT Lending Opportunities. zip and SALT Lending Opportunities.pdf.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region
Impact
- Exposure of Sensitive Data
- Credential Theft
- Information Theft and Espionage
Indicators of Compromise
Filename
- SALT Lending Opportunities[.] zip
- SALT Lending Opportunities[.]pdf[.]lnk
MD5
- 790a21734604b374cf260d20770bfc96
- e24bbbd3b32ca2fd3b8fb76f036cb4bb
SHA-256
- fff9f847b0dab68a2f219c390dc16c066e05830aa6d1bd0cd991000334b12471
- 237637563540be13fe129703821168ac337abeaa8b1868a66efd2a92d75c6bc4
SHA1
- 6efdbb446c90826378bc76a6f6fc72e11b446a76
- c2b6375844aaa4af49eead3b4a22d664f8272b4b
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.