• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
WebSetNet

WebSetNet

Technology News

  • Technology News
    • Mobile
    • Games
  • Internet Marketing
  • System Admin
    • Windows
    • Linux
    • Mac & Apple
    • Website Scripts
      • Wordpress

Windows Update used by North Korean hackers to bypass security software

February 16, 2022 by Martin6

Windows Update and GitHub were utilized in a campaign by a notorious cybercrime group.

What you need to know

  • A new campaign by the North Korean advanced persistent threat group Lazarus was recently discovered.
  • The campaign used malicious documents pretending to be about a job for Lockheed Martin as part of spear phishing attacks.
  • The Lazarus group also took advantage of Windows Update to bypass security detection mechanisms.

Malwarebytes recently discovered a campaign perpetrated by the advanced persistent threat group (APT) known as Lazarus. The campaign used spear phishing attacks that included malicious documents disguised as information about job opportunities with Lockheed Martin. As part of its attack methodology, the Lazarus group uses Windows Update and GitHub to bypass security software.

Malwarebytes thoroughly breaks down the attack in technical terms. One part of the campaign uses Windows Update to bypass security detection mechanisms. Malwarebytes notes that this is a “clever” use of Windows Update.

“This is an interesting technique used by Lazarus to run its malicious DLL using the Windows Update Client to bypass security detection mechanisms,” said Malwarebytes. “With this method, the threat actor can execute its malicious code through the Microsoft Windows Update client…”

The Lazarus group also used GitHub in its attack. Using GitHub makes it difficult for security products to tell the difference between malicious and legitimate content. This is the first time that Malwarebytes has observed the group using GitHub in this way.

“Rarely do we see malware using GitHub as C2 and this is the first time we’ve observed Lazarus leveraging it,” explained Malwarebytes. “Using GitHub as a C2 has its own drawbacks but it is a clever choice for targeted and short term attacks as it makes it harder for security products to differentiate between legitimate and malicious connections.”

The Lazarus group previously used spear phishing tactics to obtain COVID-19 research. Lazarus was also connected to the well-known attack on Sony and the WannaCry ransomware attack.

Lazarus was also alleged to be involved in the theft of $400 million worth of cryptocurrency in 2021.

Original Article

Related posts:

  1. Increasing resilience against Solorigate and other sophisticated attacks with Microsoft Defender
  2. How to fix Malwarebytes memory issues
  3. The ultimate guide to fixing problems with the May 2020 Update
  4. Microsoft Windows Security Updates February 2019 overview
  5. Microsoft Windows Security Updates September 2020 overview
  6. Monster Hunter Rise and MHR: Sunbreak (PC) list of monsters
  7. Fix Malwarebytes high CPU and Memory usage on Windows 11/10
  8. Microsoft Windows Security Updates April 2018 release overview
  9. Install Transmission 3.0 Bit Torrent Software For Ubuntu Linux
  10. Microsoft Security Updates February 2018 release

Filed Under: Windows Tagged With: epic games, icloud, Instagram, instant gaming, ip address, speedtest

Primary Sidebar

Trending

  • How to fix Windows Update Error 80244019
  • Windows 10 Update keeps failing with error 0x8007001f – 0x20006
  • How To Change Netflix Download Location In Windows 10
  • Troubleshoot Outlook “Not implemented” Unable to Send Email Error
  • How do I enable or disable Alt Gr key on Windows 10 keyboard
  • How To Install Android App APK on Samsung Tizen OS Device
  • 3 Ways To Open PST File Without Office Outlook In Windows 10
  • FIX: Windows Update error 0x800f0986
  • How to Retrieve Deleted Messages on Snapchat
  • Latest Samsung Galaxy Note 20 leak is a spec dump revealing key features
  • Install Android 7.0 Nougat ROM on Galaxy Core 2 SM-G355H
  • 192.168.1.1 Login, Admin Page, Username, Password | Wireless Router Settings
  • Websites to Watch Movies Online – 10+ Best Websites Without SignUp/Downloading
  • How to Backup SMS Messages on Your Android Smartphone
  • How to delete a blank page at the end of a Microsoft Word document
  • Fix: The Disc Image File Is Corrupted Error In Windows 10
  • Android 11 Custom ROM List – Unofficially Update Your Android Phone!
  • Samsung Galaxy Z Fold 3 could be scheduled for June 2021, with S Pen support

Footer

Tags

Amazon amazon prime amazon prime video Apple Application software epic games Galaxy Note 20 Galaxy S22 Plus Galaxy S22 Ultra Google Sheets headphones Huawei icloud Instagram instant gaming ip address iPhone iphone 12 iphone 13 iphone 13 pro max macOS Microsoft Microsoft Edge Mobile app office 365 outlook Pixel 6 Samsung Galaxy Samsung Galaxy Book 2 Pro 360 Samsung Galaxy Tab S8 Smartphone speedtest speed test teams tiktok Twitter vpn WhatsApp whatsapp web Windows 10 Windows 11 Changes Windows 11 Release Windows 11 Update Windows Subsystem For Android Windows 11 Xiaomi

Archives

  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org