Lazarus used a compromised Korean website to selectively infect visitors through vulnerable INITECH INISAFE CrossWEB EX software, according to AhnLab. The attackers subsequently exploited CVE-2021-26606 in Dream Security MagicLine4NX to compromise internal systems, used RDP, and attempted SSH access. Their activity included malicious thread injection into ftp.exe, service-based backdoor persistence, and firewall changes allowing communication over TCP port 60012. Separate reporting from Symantec identified Lazarus targeting the chemical sector; the supplied references do not establish that those targets were part of the same intrusion campaign.
AhnLab documented bring-your-own-vulnerable-driver (BYOVD) activity in which Lazarus deployed rootkit malware that used vulnerable drivers to modify kernel memory and disable anti-malware software, including AhnLab V3. This defense-evasion technique undermines endpoint protection after attackers obtain access. AhnLab recommended updating or removing the vulnerable software and enabling V3’s behavior-based detection. Defenders should also investigate unexpected driver loading, antivirus disruption, suspicious service creation, and unauthorized firewall rules permitting traffic on port 60012.

See which actors are running it and whether you're in range.
11 events from the most recent confirmed update back to the earliest known activity.
AhnLab ASEC published a separate analysis describing Lazarus's use of a Bring Your Own Vulnerable Driver rootkit attack to disable security software.
INITECH issued a vulnerability notice for INISAFE CrossWEB EX V3, the software Lazarus exploited to infect visitors to a compromised website.
Symantec reported that Lazarus used WMI to invoke MagicLine4NX on a remote system before injecting a malicious thread.
AhnLab ASEC published an analysis documenting Lazarus exploiting an INITECH process to infect systems.
A Dream Security notice documented CVE-2021-26606, a buffer overflow affecting MagicLine4NX version 1.0.0.17 and earlier that permits remote arbitrary command execution.
AhnLab published malware hashes, attacker infrastructure, and legitimate websites abused for command and control. It recommended updating or removing vulnerable INISAFE and MagicLine4NX software and enabling V3's behavior-based detection to block anti-malware-disabling activity.
In the documented execution chain, an injected thread in ftp.exe created a rootkit that deployed vulnerable DLL and driver files and registered them as a service. The rootkit obtained kernel-memory read and write capabilities and modified kernel memory to disable anti-malware programs, including AhnLab V3.
Lazarus attempted to log into SSH servers on internal systems using the root account; the report does not establish that these attempts succeeded.
After gaining access, Lazarus registered a backdoor as a service to maintain control of compromised systems. The attackers changed the host firewall to permit the backdoor's communications over TCP port 60012.
Lazarus exploited CVE-2021-26606 in Dream Security MagicLine4NX to compromise systems within internal networks and also accessed internal systems through RDP. The attackers used the MagicLine4NX process to inject a malicious thread into ftp.exe.
Lazarus modified a Korean website so malicious behavior activated only for visitors from selected IP addresses. Visitors running vulnerable INISAFE CrossWEB EX software could have SCSKAppLink.dll downloaded and executed through INISAFECrossWebEXSvc.exe.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 30 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcesymantec-enterprise-blogs.security.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.