HomeSecurityLazarus group targets US energy providers

Lazarus Group Targets US Energy Providers

The hacking group "Lazarus" (APT38) exploits VMWare Horizon servers to access the corporate networks of energy providers in the United States, Canada, and Japan.

Lazarus

Lazarus is a state-sponsored threat actor known for conducting espionage, data theft, and cryptocurrency theft campaigns over the past decade. The threat actors are responsible for hundreds of sophisticated attacks.

See also: How to install Session Messenger on Windows?

According to Cisco Talos researchers, who uncovered the latest operation, the Lazarus group targeted energy organizations between February and July 2022, leveraging public VMWare Horizon exploits for initial access.

From there, they used custom malware families, such as VSingle and YamaBot, and a previously unknown remote access trojan (RAT) named MagicRAT that is used to search and steal data from infected devices.

Symantec threat hunters analyzed the same campaign in April and ASEC researchers in May. However, Cisco's report goes deeper and reveals many details about the threat actor 's activity .

Multiple attack strategies

Cisco Talos presents several attack strategies that illustrate Lazarus' latest techniques, tactics, and procedures (TTPs) and highlight the agility of the sophisticated hacking team.

In the first case, threat actors exploit VMWare servers vulnerable to Log4Shell flaws to execute shellcode that creates a reverse shell to execute arbitrary commands on the compromised endpoint.

Lazarus

Since VMWare Horizon runs with elevated privileges, the Lazarus team can disable Windows Defender via registry key modifications, WMIC, and PowerShell commands before deploying VSingle.

See also: US: Cyberattacks against hospitals mean higher mortality rates

The VSingle backdoor supports advanced network reconnaissance commands, prepares the ground for credential theft, creates new admin users on the host, and finally, establishes a reverse shell connection to the C2 to retrieve plugins that enrich its functionality.

Lazarus Group Targets US Energy Providers

In the second case presented in the report, which involves a different victim, the initial access and identification follow similar patterns, but this time, the hackers dropped MagicRAT along with VSingle.

Talos published a separate post about MagicRAT, detailing all the functions of this trojan.

See also: Google: Former members of the Conti group attack Ukraine

MagicRAT can create persistence on its own by executing hardcoded commands that create the required scheduled tasks, help identify the system, and deliver additional malware from the C2, such as TigerRAT.

Lazarus

In the third attack, Lazarus deploys YamaBot, a custom malware written in Go, which has typical RAT.

In July 2022, the Japanese CERT linked YamaBot to the Lazarus group, highlighting its encrypted C2 communication capabilities.

The differentiation of the Lazarus attack chain is not limited to the final malware payloads, but extends to proxy or reverse tunneling tools and credential collection techniques .

In some cases, hackers used the Mimikatz and Procdump tools, while in others, they exfiltrated copies of registry hives containing AD credentials.

The idea behind these variations is to mix up TTPs and make defense and detection more challenging for incident responders.

As highlighted in this report, the Lazarus group is closely monitored by cybersecurity firms, so they cannot afford to be lazy in diversifying their attack chains.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS