HomeSecurityLazarus hacking group hides payloads in BMP image files

Lazarus hacking group hides payloads in BMP image files

The Lazarus is using new techniques to cover up its malicious activities. Security researchers have discovered a new phishing campaignin which Lazarus hackers are abusing BMP image files to infect their victims.

Lazarus BMP image files
Lazarus hacking group hides payloads in BMP image files

The Lazarus Group is a state-sponsored hacking group (APT group), said to be funded by the North Korean government.

It is one of the most prolific and sophisticated APT groups and has been active for over a decade. Researchers have found that the Lazarus group is behind major attacks on organizations around the world. It is said to be responsible for multiple WannaCry ransomware attacks, bank heists , and attacks on cryptocurrency exchanges.

See also: Lazarus Group: Hits cryptocurrency company via LinkedIn

South Korean organizations are key targets of the Lazarus group, although the group has also been linked to attacks in the US and South Africa.

In a phishing campaign detected by Malwarebytes on April 13, a document linked to Lazarus revealed the use of an interesting technique designed to hide malicious payloads in image files.

See also: The hacking group “Lazarus” targets COVID-19 vaccine research!

The phishing attack starts with a document Microsoft Office (참가 수정서 전로 .doc) in Korean. Victims are asked to enable macros to view the file's contents, which, in turn, triggers a malicious payload.

Lazarus hacking group hides payloads in BMP image files
Lazarus hacking group hides payloads in BMP image files

The macro displays a pop-up message claiming to be an old version of Office, but calls an executable HTA file, as a compressed zlib file in a PNG image file.

During decompression, the PNG is converted to BMP format and, when executed, the HTA file installs a loader for a Trojan (RAT), which is stored as “AppStore.exe” on the target machine.

See also: 100,000 Google sites used to install SolarMarket RAT

“This is a clever method used by hackers to bypass security mechanisms that can detect embedded objects within images,” the researchers say. “The reason is because the document contains a PNG image that has a zlib compressed malicious object and since it is compressed it cannot be detected. Then, the hackers used a simple conversion mechanism to decompress the malicious content.”

The RAT is able to connect to a command-and-control (C2) server, receive commands, and install shellcode. Communication between the malware and the C2 is encoded and encrypted, and relies on a custom encryption algorithm that has previously been linked to Lazarus' Bistromath RAT.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS