

Rewterz Threat Alert – Lazarus APT Group – Active IOCs
March 31, 2022
Rewterz Threat Advisory – CVE-2022-27641 – NETGEAR Vulnerability
March 31, 2022
Rewterz Threat Alert – Lazarus APT Group – Active IOCs
March 31, 2022
Rewterz Threat Advisory – CVE-2022-27641 – NETGEAR Vulnerability
March 31, 2022Severity
High
Analysis Summary
Vidar, which first appeared in late 2018, is a malware family that primarily acts as an information stealer and is frequently seen as a prelude to ransomware distribution. This malware takes data and distributes it as spam email, cracked commercial software, and keygen programs.
Vidar can scrape a wide range of digital wallets in addition to credit card data and passwords. Various campaigns can be used to propagate this malware. It allows data such as system information, browser data, and passwords to be captured and exfiltrated from a system. Vidar has also been seen as a secondary payload in ransomware attacks like STOP/DJVU.
Impact
- Data Exfiltration
- Information Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 98af8141160486e85f067ed1605296de
- 1b28a890f243870fe2292db97e0dc6a8
SHA-256
- ba63e0c94bf44bff7df015864e9e30257018b4a59a1ec6f42741e1a00d4043a4
- 11587581475665ef687e599105d575955833613e6e57d3d120aead70cddb0918
SHA-1
- 4dd6b126576839a64f40154297e9af4793e081bf
- d8b96c8545b34e29e371a189694ceb0d3757ac28
Remediation
- Block all the threat indicators at your respective controls.
- Search for IOCs in your environment.