Automatically translated.View original post

Lazarus Group is back with RemotePE malware.

Lazarus Group returns with RemotePE malware aimed at global financial firms

According to a report by the website SCWorld, the return of hackers from North Korea, the Lazarus Group, along with a new malware, RemotePE, a remote access trojan type of malware, was detected by the Fox-IT research team, part of the leading cybersecurity firm NCC Group. The research team noted that the Lazarus Group's campaign was particularly focused on the financial company and the Kryptokerrenzi group.

For the process of spreading malware into the system, a multi-layer embedded method (Multi-Stages Infection) is used to implement two different malware loaders, DPAPILoader and RemotePELoader. DPAPILoader is used to decryption and reload the RemotePELoader malware with the Windows Data Protection API. After the RemoteLoPEader malware has been loaded, the malware will contact the C2 or Command and and Control server to download the real malware RemotePE directly into the memory (In-Memory Execution). )

The capabilities of this malware can be called very versatile because it can receive a variety of commands from the C2 server, covering file management on the victim's machine (File Operations), Process Manipulation, and Self-Management. Not only does the malware have features to use a variety of file deletion methods, such as overwriting the original file several times before deleting it. In addition, the malware uses a variety of techniques to evade detection, such as patching the Windows event tracking feature or Event Tracing for Windows (ETW). It is not possible to track malware movements on the system and use Hell's Gate techniques to evade EDR or Endpoint Detection and Response.

# Trending # Lemon 8 Howtoo # lemon 8 diary # lazarusgroup # freedomhack

6/20 Edited to

... Read moreจากประสบการณ์ส่วนตัวในการติดตามข่าวสารและพฤติกรรมของกลุ่มแฮกเกอร์อย่าง Lazarus Group พบว่าความเฉียบคมของมัลแวร์ RemotePE ในครั้งนี้สะท้อนถึงความพัฒนาอย่างรวดเร็วในเทคนิควิธีการโจมตีทางไซเบอร์ ซึ่งใช้วิธีการฝังมัลแวร์แบบหลากชั้น (Multi-Stages Infection) โดยผ่านตัว Loader สองชั้น คือ DPAPILoader และ RemotePELoader ซึ่งช่วยให้มัลแวร์สามารถถูกดาวน์โหลดและรันในหน่วยความจำโดยตรงได้ โดยไม่ต้องเขียนไฟล์ลงดิสก์แบบทั่วไป ถือเป็นเทคนิคที่ทำให้ฝ่ายป้องกันตรวจจับได้ยากมาก นอกจากนี้ ฟีเจอร์ที่น่ากลัวของ RemotePE คือความสามารถในการรับคำสั่งที่หลากหลายจากเซิร์ฟเวอร์ C2 ตั้งแต่การจัดการไฟล์ การควบคุมโปรเซส รวมถึงฟีเจอร์ลบไฟล์แบบเขียนทับหลายครั้งก่อนลบจริง ช่วยปิดร่องรอยหลังการโจมตี ทำให้การสืบสวนสอบสวนความเสียหายทำได้ยากขึ้นมาก ในมุมของการป้องกันองค์กรการเงินและบริษัทคริปโตที่มีความเสี่ยงสูง แนะนำให้เสริมความเข้มงวดด้านการรักษาความปลอดภัยไซเบอร์ เช่น การใช้ EDR ที่มีความสามารถตรวจจับเทคนิคขั้นสูง การตั้งค่าระบบให้จำกัดสิทธิ์เข้าถึงไฟล์ที่สำคัญอย่างเคร่งครัด รวมถึงการอัปเดตซอฟต์แวร์และระบบปฏิบัติการอย่างสม่ำเสมอ เพราะถ้าเกิดมัลแวร์มีเทคนิคหลบเลี่ยงการตรวจจับ เหล่านี้อาจช่วยลดความเสี่ยงเบื้องต้นได้อย่างมีประสิทธิภาพ สุดท้ายนี้ ผู้ใช้งานทั่วไปเองก็ควรมีความรู้และตระหนักถึงภัยคุกคามไซเบอร์เหล่านี้ หลีกเลี่ยงการเปิดไฟล์แนบหรือคลิกลิงก์ที่ไม่น่าเชื่อถือ และลงทะเบียนข่าวสารจากผู้ให้บริการความปลอดภัยไซเบอร์เพื่อรับข้อมูลอัปเดตเร็วที่สุด เพราะอย่างที่เห็นว่าแฮกเกอร์สามารถพัฒนาเทคนิคและมัลแวร์ใหม่ๆ ที่ท้าทายระบบรักษาความปลอดภัยอยู่ตลอดเวลา การเตรียมตัวและระมัดระวังถือเป็นด่านแรกที่สำคัญที่สุดในการป้องกันความเสียหายที่จะเกิดขึ้น