Lazarus Group Exploits Zoho ManageEngine Vulnerability to Target Internet Backbone Infrastructure Provider

The Lazarus Group, a North Korea-linked advanced persistent threat (APT) actor known for its sophisticated cyber attacks, has recently been observed exploiting a vulnerability in Zoho ManageEngine. This exploit led to the compromise of an internet backbone infrastructure provider in Europe. In this article, we will delve into the details of the attack, the timeline, Lazarus Group’s exploitation of the vulnerability, and the implications it holds for organizations around the world.

The attack and timeline

The attack took place in early 2023, just days after proof-of-concept (PoC) exploit code targeting the Zoho ManageEngine flaw was made public. This discovery highlights the inherent risks associated with the release of PoC code. Cybercriminals, like the Lazarus Group, quickly seize the opportunity to leverage such exploits to their advantage, leaving organizations vulnerable to attacks.

Lazarus’ exploitation of CVE-2022-47966

The Lazarus Group utilized the CVE-2022-47966 vulnerability to deploy a new variant of a remote access trojan (RAT) named QuiteRAT. It is essential to note that the successful exploitation of this vulnerability demonstrates the group’s advanced technical capabilities and their ability to adapt their tactics to exploit newly discovered vulnerabilities.

Functionality and Persistence of QuiteRAT

Once executed on a compromised machine, QuiteRAT has the capability to harvest system information, which it then sends to the attackers’ server. Furthermore, QuiteRAT allows the attackers to engage in further system reconnaissance and achieve persistence by modifying the Windows registry. These features grant them prolonged access to the compromised system, enabling them to extract sensitive information and potentially launch further attacks.

Similarities between QuriteRAT and MagicRAT

QuiteRAT, which has been observed in recent Lazarus Group attacks, is notably smaller in size compared to its predecessor, MagicRAT. Additionally, QuiteRAT lacks a built-in persistence mechanism. Both implants employ Base64 encoding to obfuscate their strings and showcase similar functionality aimed at remaining dormant on the endpoint, making detection and analysis more challenging.

Lazarus’ transition to QuiteRAT

Lazarus Group’s decision to replace MagicRAT with QuiteRAT in their recent attacks raises questions about their motives and the strategic shift in their toolset. The move may indicate evolving tactics or an attempt to exploit new vulnerabilities undetected. Understanding this transition is crucial for organizations to anticipate future attacks and take proactive measures to secure their networks.

Lazarus’s targeting of other entities

The attack on the internet backbone infrastructure provider is not an isolated incident. The Lazarus Group has also been targeting healthcare entities in Europe and the US, emphasizing the far-reaching impact and significance of their operations. These attacks highlight the group’s intent to access critical systems and potentially compromise sensitive data, posing a severe threat to the targeted organizations and their stakeholders.

In response to these attacks, Zoho has released patches to address the ManageEngine vulnerability (CVE-2022-47966) for the impacted products. However, this incident serves as a significant reminder of the constant need for vigilance and the importance of promptly implementing security updates and patches. Organizations must remain proactive in assessing their systems’ vulnerabilities, staying informed about emerging threats, and fostering a robust cybersecurity posture to safeguard their networks and sensitive information from the persistent threat posed by groups like Lazarus.

Explore more

How Will Adobe Brand Visibility Redefine the AI Search Era?

The evolution of digital information retrieval has reached a critical inflection point where traditional search engine results pages are no longer the primary gateway for consumer decision-making. As generative AI models and intelligent agents become the preferred method for research and discovery, brands face an existential challenge in maintaining their presence within these black-box systems. Adobe Brand Visibility addresses this

Trend Analysis: AI-Driven Vulnerability Detection

The digital landscape is currently witnessing a tectonic shift as artificial intelligence evolves from a mere defensive tool into a relentless high-speed auditor capable of dismantling the complex architecture of modern software in seconds. This automation revolution has sent a shockwave through the global tech industry, signaling an era where machines are now uncovering hundreds of software flaws simultaneously. In

Dashlane Bolsters Security After Targeted API Attack

Dominic Jainy is a seasoned IT professional whose expertise sits at the intersection of high-stakes cybersecurity, artificial intelligence, and blockchain infrastructure. With a career dedicated to understanding how complex systems fail and how they can be reinforced, Jainy has become a go-to voice for dissecting large-scale digital breaches. His analytical approach focuses not just on the code, but on the

AI Is Revitalizing the Trades and the Physical Economy

The Strategic Intersection: Silicon Valley and the Skilled Trades The massive migration of capital from purely virtual ecosystems to the gritty foundations of our physical infrastructure marks the most significant economic realignment of the current decade. For years, the digital gold rush focused primarily on social media and software-as-a-service, but the current environment demands a return to brick, mortar, and

Can Musk and Intel Solve the Impending AI Supply Crisis?

The global race for artificial intelligence has reached a fever pitch, but a sobering question looms over the industry: can the physical world actually produce the silicon required to power these dreams? While software capabilities are doubling at a breakneck pace, the semiconductor industry is hitting a wall of resource scarcity and infrastructure limits. The partnership between Elon Musk’s aggressive