Wednesday, April 16, 2025
HomeMalwareLazarus APT Hackers Attack Japanese Organization Using Remote SMB Tool "SMBMAP" After...

Lazarus APT Hackers Attack Japanese Organization Using Remote SMB Tool “SMBMAP” After Network Intrusion

Published on

SIEM as a Service

Follow Us on Google News

Researchers from JPCERT/CC observed that the world’s most dangerous APT hackers attack Japanese organization with different malware for during and after the intrusion on the targeted network.

Lazarus is also known as Hidden Cobra is a North Korean APT hacker group that has been involved with various high profile cyber-attacks various government and private sectors around the globe since 2009.

Lazarus hacker group believed to be working under the North Korean state-sponsored hacking organization Reconnaissance General Bureau and using various attack methods such as Zerodays, spearphishing, malware, disinformation, backdoors, droppers.

- Advertisement - Google News

Attackers using the obfuscated malware for the ongoing attack against Japanese organizations with some of the sophistication functionalities to gain access to the network for the various malicious activities.

One of the Malware Infection Process

The initial stage of the infection starts with download and executes the configuration modules and stored in the specific folder C:¥Windows¥System32¥.

Attackers added some unnecessary files and bundled it as ZIP which contains more than 150 MB data, and the file is obfuscated used VMProtect.

The initial configuration file of the malware is completely encrypted, later it is stored in the registry entry and loaded automatically when the malware gets executed.

Here the complete malware behavior, configuration, communication format and modules.

APT Malware behavior

Attackers encrypted all the Strings in the Malware with AES128 and hardcoded the Encryption key.

According to the JPCERT/CC Report “Since the malware converts the 16-letter string to wide character (32 bytes), only the first 16 bytes is used as a key.”

“Windows API name is also AES-encrypted. After decrypting API strings, the address for the APIs that are called by LoadLibrary and GetProcAddress are resolved.”

After the successful infection malware, send the HTTP request to C2 server with the following information:-

Later the malware focus to downloading a module from the C2 server through various communication attempt. once it is successfully downloaded, it requests the command from the C2 server where the attackers send the specific commands.

Download the module will be having the various functionality of the following:-

  • Operation on files (create a list, delete, copy, modify time created)
  • Operation on processes (create a list, execute, kill)
  • Upload/download files
  • Create and upload a ZIP file of arbitrary directory
  • Execute arbitrary shell command
  • Obtain disk information
  • Modify system time

Finally, attackers spread the infection and leveraging account information with help of the Python tool “SMBMAP” which allows access to the remote host via SMB after converting it as a Windows PE file with Pyinstaller.

You can get the details about Indicator of Compromise here.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Landmark Admin Suffers Major Breach, Exposing Data of 1.6M+ Users

Landmark Admin, LLC (“Landmark”), a Texas-based third-party administrator for life insurance carriers, has confirmed...

SquareX to Reveal Critical Data Splicing Attack at BSides SF, Exposing Major DLP Vulnerability

SquareX researchers Jeswin Mathai and Audrey Adeline will be disclosing a new class of data exfiltration techniques at BSides...

Firefox Fixes High-Severity Vulnerability Causing Memory Corruption via Race Condition

Mozilla has released Firefox 137.0.2, addressing a high-severity security flaw that could potentially allow...

Tails 6.14.2 Released with Critical Fixes for Linux Kernel Vulnerabilities

The Tails Project has urgently released Tails 6.14.2, addressing critical security vulnerabilities in the Linux...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Chinese Hackers Unleash New BRICKSTORM Malware to Target Windows and Linux Systems

A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted...

Malicious Macros Return in Sophisticated Phishing Campaigns

The cybersecurity landscape of 2025 is witnessing a troubling resurgence of malicious macros in...

Hackers Exploit Node.js to Spread Malware and Exfiltrate Data

Threat actors are increasingly targeting Node.js—a staple tool for modern web developers—to launch sophisticated...