Kaspersky shares details of cyberattack targeting organizations worldwide

The Kaspersky Global Research and Analysis Team (GReAT) has uncovered a new campaign by the malicious Lazarus group targeting organizations across the globe.

AA

According to a statement from Kaspersky, the GReAT team detected a cybersecurity incident in which targets were infected via legitimate software designed to encrypt web communications through digital certificates.

Although the security vulnerabilities in question were reported and patches were released, organizations worldwide continue to use the flawed version of the software, providing an entry point for the Lazarus attack group.

The attackers deployed "SIGNBT" malware, which features a highly complex structure and uses advanced evasion techniques to control the victim. They also utilized the LPEClient tool, which is known to have previously targeted defense industry contractors, nuclear engineers, and the cryptocurrency sector.

CONSISTENT WITH TACTICS USED BY THE LAZARUS GROUP

This malware acts as the initial point of infection and plays a significant role in profiling the victim and delivering the payload. Observations by Kaspersky researchers show that the role of LPEClient in this and other attacks is consistent with the tactics used by the Lazarus group, as seen in the 3CX supply chain attack.

As the investigation deepened, it was revealed that the Lazarus malware had targeted its first victim, a software vendor, several times before. This recurring attack pattern points to a determined and focused effort, likely intended to steal critical source code or disrupt the software supply chain.

'OPERATING ON A GLOBAL SCALE'

The threat actor consistently exploited vulnerabilities in the company's software and expanded its scope by targeting other companies using unpatched versions of the software. Kaspersky's Endpoint Security solution proactively detected the threat and prevented further attacks against other targets.

In the statement, Seongsu Park, Lead Security Researcher at Kaspersky's Global Research and Analysis Team, said, "The ongoing activities of the Lazarus group are a testament to their advanced capabilities and unwavering motivation. They operate on a global scale and target a wide variety of sectors through various methods. This points to an ongoing and evolving threat that requires greater attention."

According to the statement, Kaspersky researchers recommend the following measures to avoid becoming a victim of a targeted attack by a known or unknown threat actor:

"Regularly update your operating system, applications, and antivirus software to close known security vulnerabilities. Be cautious of emails, messages, or calls requesting your sensitive information. Verify the sender's identity before sharing any personal information or clicking on suspicious links. Provide your SOC team with access to the latest threat intelligence (TI)."