
The North Korean state-backed hacker group Lazarus is invading Windows Internet Information Service (IIS) web servers to exploit them for the distribution of malware.
See also: Are Lazarus hackers behind the JumpCloud hack?
IIS is Microsoft's web server solution used to host websites or application services, such as Microsoft Exchange.
South Korean security analysts at ASEC previously reported that Lazarus targeted IIS servers to gain initial access to corporate networks. Today, the cybersecurity firm reports that hackers are also exploiting poorly protected IIS services to distribute malware.
The main advantage of this technique is the ease of infecting website visitors or users of services hosted on compromised IIS belonging to trusted organizations.
Attacks in South Korea
Lazarus, compromised legitimate South Korean websites to perform “Watering Hole” attacks on visitors using a vulnerable version of the INISAFE CrossWeb EX V6 software. This software is used by many organizations in South Korea for electronic financial transactions, security certification, online banking, etc. The vulnerability was previously documented by Symantec and ASEC in 2022. The attack is initiated when a malicious HTM file is downloaded and injected into the INISAFE Web EX Client. The exploit of the flaw brings a malicious payload ‘SCSKAppLink.dll’ from an IIS web server that has already been compromised before the attack and is used as a malware distribution server.
ASEC did not analyze the specific payload, but says it is likely a malware downloader that has been seen in other recent Lazarus campaigns.
Lazarus then uses the privilege escalation malware “JuicyPotato” (“usopriv.exe”) to gain higher-level access to the compromised system.
Suggestion: Lazarus hackers: Link to 3CX attack and target Linux users with fake job offers

JuicyPotato is used to execute a second malware transporter ('usoshared.dat') that decrypts the downloaded data files and executes them in memory to bypass AV.

ASEC recommends that users of NISAFE CrossWeb EX V6 update the software to its latest version, as the exploitation of the product's known vulnerabilities by Lazarus has been ongoing since at least April 2022. The security company advises users to upgrade to version 3.3.2.41 or later and refers to remediation instructions it published four months ago, highlighting the Lazarus threat.
Microsoft application servers are becoming a popular target for hackers who use them to distribute malware, likely due to their trusted nature.
Read also: GitHub: Lazarus hackers target devs with malicious projects
source of information:bleepingcomputer.com
