[ << ALL_FEED ]

Metamorphosis of Lazy Koala

Latest materials

Lazy Koala’s Metamorphosis. It was Koala 🐨 — now it’s Capybara 😎

In May of this year, new attacks by the Lazy Koala group against Azerbaijan, Belarus, and Uzbekistan were recorded.

In the case of the attacks on Azerbaijan and Belarus, the format of the messages sent to the bot changed; the hackers also stopped using a single account in attacks and changed the nickname from Koala to Capybara.

Traditionally, when the group’s malware is launched, an embedded document opens that distracts the victim’s attention and contains a current regional news item (an example is in the screenshot).

LazyStealer has also changed somewhat; now the PYD files (which contain the lure) have new names:

CapybaraPDF.cp39-win_amd64.pyd

Also, the name of the main script includes an abbreviation of the name of the targeted country:

bls.py, az.py

In addition to the Pyarmor protector, another layer of protection was added: the data is now base64-encoded and zlib-compressed; after all obfuscation is removed, the script is launched via exec. The deobfuscated script has the same functionality, but its structure and the function names themselves have been slightly changed.

In the case of the attacks on Uzbekistan, the changes were as follows:

• Now hosting is used in the C2 infrastructure instead of a Telegram bot.
• As a lure, the attackers send a DOCX file instead of a PDF file.

IoCs:

601f11b308286673d9022df4e875cf86be71235b6a413d63dfd0d0f553c4bed8

42f79b6ede5e6d048a9bf419f5751ff1d4046e7a656a84fab4e97fdfb1ed4f0d

da91f1f8279edae524ce98df0b6d1aca52336f723e3b8bcb7c8a0933c4b2eb0d

@ptescalator

More from global_author

More from global_author

Latest materials