216.73.216.6

Analysis of Lazarus Group's Attack Targeting Windows Web Servers

· Published 11/03/2025 14:20 · Modified 11/03/2025 16:53

Export JSON

Essential information

Published
11/03/2025 14:20
Modified
11/03/2025 16:53
Tags
2025-03-11 c2 proxy iis lazarloader privilege-escalation uac bypass web servers webshell windows
Related entities
1 intrusion sets (apt), 8 techniques (mitre), 1 malware, 1 others

Description

The Lazarus group has been targeting , particularly in South Korea, installing webshells and C2 scripts to use compromised servers as proxies. The attacks involve multiple stages, including the use of malware and privilege escalation tools. The C2 scripts act as proxies between the malware and secondary C2 servers. Various webshells were identified, including RedHat Hacker and custom ASP shells. The downloader was used to fetch additional payloads, while a privilege escalation tool exploited techniques. The attackers aim to establish persistence and gain elevated access on compromised systems.

External references