Open KadeMorton opened 6 years ago
Timeline of campaigns ultimately related to PowerRatankba https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Script output showing PowerSpritz PowerShell encoded and decoded command https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
PowerSpritz retrieving Base64-encoded PowerRatankba https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Malicious LNK AppLocker bypass to retrieve payload https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
CHM lures utilized in attempts to deliver PowerRatankba https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Malicious code embedded in CHM to download a VBScript PowerRatankba downloader https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
BITSAdmin retrieving malicious payload over HTTP https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
PowerShell utilized in CHM to retrieve PowerRatankba downloader VBS https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Leftover code in 5_6283065828631904327.chm https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Obfuscated falconcoin.js https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Deobfuscated falconcoin.js revealing PowerRatankba and decoy PDF URLs https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Decoys downloaded or sent along with PowerRatankba JavaScript downloaders https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Spearphishing email spoofed sender and subject
IRS themed Word document PowerRatankba downloader https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
IRS-themed malicious document macro https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Malicious Bithumb Excel spreadsheet with English option shown, with stolen branding
“About Bithumb.pdf decoy” document inside Bithumb.zip archive, with stolen branding https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf
Base64 encoded PowerRatankba downloader embedded in bithumb.xls
Flow of PowerRatankba activity from victims to the Lazarus Group operators https://www.proofpoint.com/sites/default/files/pfpt-us-wp-north-korea-bitten-by-bitcoin-bug.pdf