LightlessCan Backdoor Deployed by North Korean Lazarus APT

The Lazarus Group, a hacker collective operating out of North Korea, has employed a new form of advanced malware in their deceptive job scams, which researchers caution is significantly harder to detect than its predecessor.

While examining a recent fake job attack on a Spanish aerospace company, researchers discovered a previously unknown backdoor named LightlessCan.

The Lazarus Group's fraudulent job tactic typically involves deceiving victims with fake employment offers at renowned companies. The attackers lure victims to download a disguised malicious payload in the form of documents to cause various forms of harm.

According to researchers, the new LightlessCan payload represents a significant improvement compared to its predecessor, BlindingCan.

LightlessCan Received Significant Stealth Upgrade

LightlessCan emulates the functions of a wide range of native Windows commands, allowing for discreet execution within the RAT itself rather than through console executions that might trigger some red flags.

This method provides a significant advantage in terms of evasion, both in eluding real-time monitoring solutions like EDRs and digital forensic tools used after an attack has taken place.

The new payload also employs what the researchers called "execution guardrails," ensuring that the payload can only be decrypted on the intended victim's machine, thereby preventing unintended decryption by security researchers.

The novel malware was used in an attack on a Spanish aerospace firm when an employee received a message from a counterfeit Meta recruiter named Steve Dawson.

Shortly thereafter, the hackers sent two straightforward coding challenges embedded with the malware. Cyberespionage was the primary motive behind the Lazarus Group's attack on the Spain-based aerospace firm.

Since 2016, North Korean hackers have allegedly stolen approximately $3.5 billion from cryptocurrency projects, according to a September 14 report by the blockchain forensics firm Chainalysis.

October 2, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.