{"id":54393,"date":"2023-03-07T07:31:00","date_gmt":"2023-03-06T23:31:00","guid":{"rendered":"http:\/\/www.upgrademag.com\/web\/?p=54393"},"modified":"2023-03-02T16:33:13","modified_gmt":"2023-03-02T08:33:13","slug":"eset-discovers-winordll64-backdoor-likely-part-of-lazarus-arsenal","status":"publish","type":"post","link":"http:\/\/www.upgrademag.com\/web\/2023\/03\/07\/eset-discovers-winordll64-backdoor-likely-part-of-lazarus-arsenal\/","title":{"rendered":"ESET discovers WinorDLL64 backdoor, likely part of Lazarus arsenal"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>ESET researchers discovered the WinorDLL64 backdoor, one of the payloads of the Wslink downloader. The targeted region, and overlap in behavior and code, suggest the tool is used by the infamous North Korea-aligned APT group Lazarus. Wslink\u2019s payload can exfiltrate, overwrite, and remove files, execute commands, and obtain extensive information about the underlying system.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWslink, which has the filename WinorLoaderDLL64.dll, is a loader for Windows binaries that, unlike other such loaders, runs as a server and executes received modules in memory. As the wording suggests, a loader serves as a tool to load a payload, or the actual malware, onto the already compromised system,\u201d explains Vladislav Hr\u010dka, the ESET researcher who made the discovery. \u201cThe Wslink payload can be leveraged later for lateral movement, due to its specific interest in network sessions. The Wslink loader listens on a port specified in the configuration and can serve additional connecting clients, and even load various payloads,\u201d he adds.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">WinorDLL64 contains overlaps in both behavior and code with several Lazarus samples, which indicates that it might be a tool from the vast arsenal of this North Korea-aligned APT group.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The initially unknown Wslink payload was uploaded to VirusTotal from South Korea shortly after the publication of an ESET Research blog post on the Wslink loader. ESET telemetry has seen only a few detections of the Wslink loader in Central Europe, North America, and the Middle East. Researchers from AhnLab confirmed South Korean victims of Wslink in their telemetry, which is a relevant indicator, considering the traditional Lazarus targets and that ESET Research observed only a few detections.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Active since at least 2009, this infamous North Korea-aligned group is responsible for high-profile incidents such as the\u00a0Sony Pictures Entertainment hack, the tens-of-millions-of-dollars\u00a0cyberheists in 2016, the\u00a0WannaCryptor\u00a0(aka WannaCry) outbreak in 2017, and a long history of disruptive attacks against\u00a0South Korean public and critical infrastructure\u00a0since at least 2011. US-CERT and the FBI call this group HIDDEN COBRA.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more technical information about WinorDLL64, check out the blog post \u201c<a href=\"https:\/\/www.welivesecurity.com\/2023\/02\/23\/winordll64-backdoor-vast-lazarus-arsenal\/\">WinorDLL64: A backdoor from the vast Lazarus arsenal?<\/a>\u201d on WeLiveSecurity.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Wslink\u2019s payload can exfiltrate, overwrite, and remove files, execute commands, and obtain extensive information about the underlying system.<\/p>\n","protected":false},"author":6,"featured_media":47558,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[19],"tags":[286,54,2103],"class_list":["post-54393","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-headlines","tag-it-security","tag-security","tag-security-breach"],"_links":{"self":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/54393","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/comments?post=54393"}],"version-history":[{"count":0,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/posts\/54393\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media\/47558"}],"wp:attachment":[{"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/media?parent=54393"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/categories?post=54393"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.upgrademag.com\/web\/wp-json\/wp\/v2\/tags?post=54393"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}