Employees at Ashot Ashkelon Industries Limited, a subsidiary of Israel Military Industries, were targeted in a spear-phishing campaign that used a Hebrew-language lure posing as a SysAid software update. The email carried a malicious archive, SysAid-Documentation.rar, which exploited the WinRAR ACE path traversal flaw CVE-2018-20250 to place malware in the Windows Startup folder and gain persistence. Researchers linked the operation to a Lazarus-associated cluster and said the primary payload, ekrnview.exe, gathered host information and sent it to hardcoded command-and-control servers through HTTP POST fields including alive, name, key, page, and session_data.
The investigation also uncovered attacker infrastructure and related samples suggesting broader Middle East targeting. One exposed command-and-control server hosted a B374k webshell, while shortcut and working-directory artifacts pointed to tailored targeting and operator development traces such as the usernames john and Albany. Separate samples tied to the same CVE-2018-20250 exploitation chain dropped a fake Telegram Desktop.exe and a Base64-encoded .NET payload, overlapping with activity tracked by 360 as APT-C-27 (Goldmouse) and indicating a wider campaign using WinRAR exploit lures against regional defense-related targets.

Get the infrastructure and lures behind it.
5 events from the most recent confirmed update back to the earliest known activity.
Haaretz reported on March 26, 2019 that a North Korea-linked Lazarus cyberattack targeting an Israeli company had been detected. The reporting brought public attention to the intrusion against Ashot Ashkelon Industries Limited.
A related 32-bit .NET payload named "Telegram Desktop.exe" tied to similar ACE-exploit activity was built on March 11, 2019. The sample contained a PDB path referencing the username "Albany" and was associated with Middle East-targeting activity linked by ti.360.net to APT-C-27 (Goldmouse).
A second malicious file named "SysAid-Documentation.rar" was uploaded to VirusTotal from Israel on March 10, 2019. It matched the first sample except for different targeted Windows usernames in the Startup path, including "idans" and "ronpe."
On March 7, 2019, attackers sent a Hebrew-language spear-phishing email to an employee of Ashot Ashkelon Industries Limited, impersonating a SysAid software update. The attached file, "SysAid-Documentation.rar," exploited CVE-2018-20250 to drop "ekrnview.exe" into the Windows Startup path for persistence.
The malicious 64-bit Windows payload "ekrnview.exe" used in the campaign was compiled on February 26, 2019 at 04:37 KST. It was later configured to be dropped into the victim's Windows Startup folder via the WinRAR ACE exploit.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.