ATT&CKReferencesQualys LolZarus

Qualys LolZarus

Pradhan, A. (2022, February 8). LolZarus: Lazarus Group Incorporating Lolbins into Campaigns. Retrieved March 22, 2022.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples19

TechniqueUsed byProcedure example
T1027.013
Encrypted/Encoded File
GroupLazarus Group

Lazarus Group has used multiple types of encryption and encoding for their payloads, including AES, Caracachs, RC4, XOR, Base64, and other tricks such as creating aliases in code for Native API function names.

T1036.003
Rename Legitimate Utilities
GroupLazarus Group

Lazarus Group has renamed system utilities such as wscript.exe and mshta.exe.

T1036.005
Match Legitimate Resource Name or Location
GroupLazarus Group

Lazarus Group has renamed malicious code to disguise it as Microsoft's narrator and other legitimate files.

T1047
Windows Management Instrumentation
GroupLazarus Group

Lazarus Group has used WMIC for discovery as well as to execute payloads for persistence and lateral movement.

T1053.005
Scheduled Task
GroupLazarus Group

Lazarus Group has used schtasks for persistence including through the periodic execution of a remote XSL script or a dropped VBS payload.

T1059.003
Windows Command Shell
GroupLazarus Group

Lazarus Group malware uses cmd.exe to execute commands on a compromised host. A Destover-like variant used by Lazarus Group uses a batch file mechanism to delete its binaries from the system.

T1059.005
Visual Basic
GroupLazarus Group

Lazarus Group has used VBA and embedded macros in Word documents to execute malicious code.

T1071.001
Web Protocols
GroupLazarus Group

Lazarus Group has conducted C2 over HTTP and HTTPS.

T1083
File and Directory Discovery
GroupLazarus Group

Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives.

T1105
Ingress Tool Transfer
GroupLazarus Group

Lazarus Group has downloaded files, malware, and tools from its C2 onto a compromised host.

T1106
Native API
GroupLazarus Group

Lazarus Group has used the Windows API ObtainUserAgentString to obtain the User-Agent from a compromised host to connect to a C2 server. Lazarus Group has also used various, often lesser known, functions to perform various types of Discovery and Process Injection.

T1140
Deobfuscate/Decode Files or Information
GroupLazarus Group

Lazarus Group has used shellcode within macros to decrypt and manually map DLLs and shellcode into memory at runtime.

T1202
Indirect Command Execution
GroupLazarus Group

Lazarus Group persistence mechanisms have used forfiles.exe to execute .htm files.

T1204.002
Malicious File
GroupLazarus Group

Lazarus Group has attempted to get users to launch a malicious Microsoft Word attachment delivered via a spearphishing email.

T1218
System Binary Proxy Execution
GroupLazarus Group

Lazarus Group lnk files used for persistence have abused the Windows Update Client (wuauclt.exe) to execute a malicious DLL.

T1218.005
Mshta
GroupLazarus Group

Lazarus Group has used mshta.exe to execute HTML pages downloaded by initial access documents.

T1566.001
Spearphishing Attachment
GroupLazarus Group

Lazarus Group has targeted victims with spearphishing emails containing malicious Microsoft Word documents.

T1574.013
KernelCallbackTable
GroupLazarus Group

Lazarus Group has abused the KernelCallbackTable to hijack process control flow and execute shellcode.

T1620
Reflective Code Loading
GroupLazarus Group

Lazarus Group has changed memory protection permissions then overwritten in memory DLL function code with shellcode, which was later executed via KernelCallbackTable hijacking. Lazarus Group has also used shellcode within macros to decrypt and manually map DLLs into memory at runtime.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.