Metamorphosis of Lazy Koala

Latest materials
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…
Lazy Koala’s Metamorphosis. It was Koala 🐨 — now it’s Capybara 😎
In May of this year, new attacks by the Lazy Koala group against Azerbaijan, Belarus, and Uzbekistan were recorded.
In the case of the attacks on Azerbaijan and Belarus, the format of the messages sent to the bot changed; the hackers also stopped using a single account in attacks and changed the nickname from Koala to Capybara.
Traditionally, when the group’s malware is launched, an embedded document opens that distracts the victim’s attention and contains a current regional news item (an example is in the screenshot).
LazyStealer has also changed somewhat; now the PYD files (which contain the lure) have new names:
CapybaraPDF.cp39-win_amd64.pyd
Also, the name of the main script includes an abbreviation of the name of the targeted country:
bls.py, az.py
In addition to the Pyarmor protector, another layer of protection was added: the data is now base64-encoded and zlib-compressed; after all obfuscation is removed, the script is launched via exec. The deobfuscated script has the same functionality, but its structure and the function names themselves have been slightly changed.
In the case of the attacks on Uzbekistan, the changes were as follows:
• Now hosting is used in the C2 infrastructure instead of a Telegram bot.
• As a lure, the attackers send a DOCX file instead of a PDF file.
IoCs:
601f11b308286673d9022df4e875cf86be71235b6a413d63dfd0d0f553c4bed8
42f79b6ede5e6d048a9bf419f5751ff1d4046e7a656a84fab4e97fdfb1ed4f0d
da91f1f8279edae524ce98df0b6d1aca52336f723e3b8bcb7c8a0933c4b2eb0d

Latest materials
- Out-of-bounds write in ntfs!PageUpdateAnalysis
A heap buffer overflow vulnerability exists in the ntfs!PageUpdateAnalysis function of the Microsoft Windows NTFS driver.…
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- We helped Apple fix a vulnerability in the kernel of its operating systems
We helped Apple fix a vulnerability in the kernel of its operating systems PT ESC expert…
- Recovering EVTX records: carving methods
Recovering EVTX records: carving methods 🧩 When investigating incidents where attackers encrypt virtual machine images, a…





