Lazarus hackers hijack Microsoft IIS servers to spread malware

Share:

The North Korean state-sponsored Lazarus hacking group is breaching Windows Internet Information Service (IIS) web servers to hijack them for malware distribution.

IIS is Microsoft’s web server solution used to host websites or application services, such as Microsoft Exchange’s Outlook on the Web.

South Korean security analysts at ASEC previously reported that Lazarus was targeting IIS servers for initial access to corporate networks. Today, the cybersecurity company says that the threat group leverages poorly protected IIS services for malware distribution too.

The main advantage of this technique is the ease of infecting visitors of websites or users of services hosted on breached IIS servers owned by trustworthy organizations.

Attacks on South Korea

In the recent attacks observed by ASEC’s analysts, Lazarus compromised legitimate South Korean websites to perform ‘Watering Hole’ attacks on visitors using a vulnerable version of the INISAFE CrossWeb EX V6 software.

Many public and private organizations in South Korea use this particular software for electronic financial transactions, security certification, internet banking, etc.

The INISAFE vulnerability was previously documented by both Symantec and ASEC in 2022, explaining that it was exploited using HTML email attachments at the time.

“A typical attack begins when a malicious HTM file is received, likely as a malicious link in an email or downloaded from the web. The HTM file is copied to a DLL file called scskapplink.dll and injected into the legitimate system management software INISAFE Web EX Client,” explains the 2022 report by Symantec.

Exploiting the flaw fetches a malicious ‘SCSKAppLink.dll’ payload from an IIS web server already compromised before the attack for use as a malware distribution server.

“The download URL for ‘SCSKAppLink.dll’ was identified as being the aforementioned IIS web server,” explains ASEC’s new report.

“This signifies that the threat actor attacked and gained control over IIS web servers before using these as servers for distributing malware.”

ASEC did not analyze the particular payload but says it is likely a malware downloader seen in other recent Lazarus campaigns.

Next, Lazarus uses the ‘JuicyPotato’ privilege escalation malware (‘usopriv.exe’) to gain higher-level access to the compromised system.

Using JuicyPotato in the attacks
JuicyPotato in action (ASEC)

JuicyPotato is used for executing a second malware loader (‘usoshared.dat’) that decrypts downloaded data files and executes them into memory for AV evasion.

Loading the decrypted executable in memory
Loading the decrypted executable in memory (ASEC)

ASEC recommends that NISAFE CrossWeb EX V6 users update the software to its latest version, as Lazarus’ exploitation of known vulnerabilities in the product has been underway since at least April 2022.

The security company advises users to upgrade to version 3.3.2.41 or later and points to remediation instructions it posted four months ago, highlighting the Lazarus threat.

Microsoft application servers are becoming a popular target for hackers to use in malware distribution, likely due to their trusted nature.

Just last week, CERT-UA and Microsoft reported that Russian Turla hackers were using compromised Microsoft Exchange servers to deliver backdoors to their targets.

 

(c) Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
9:44 pm, Jun 1, 2025
weather icon 17°C
L: 17° | H: 18°
scattered clouds
Humidity: 65 %
Pressure: 1014 mb
Wind: 14 mph WSW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 30%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:49 am
Sunset: 9:07 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
17° | 18°°C 0 mm 0% 8 mph 65 % 1014 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
11° | 21°°C 0 mm 0% 12 mph 77 % 1018 mb 0 mm/h
Tue Jun 03 10:00 pm
weather icon
11° | 20°°C 0.74 mm 74% 17 mph 88 % 1013 mb 0 mm/h
Wed Jun 04 10:00 pm
weather icon
10° | 16°°C 0.44 mm 44% 10 mph 78 % 1010 mb 0 mm/h
Thu Jun 05 10:00 pm
weather icon
12° | 19°°C 1 mm 100% 15 mph 97 % 1006 mb 0 mm/h
Today 10:00 pm
weather icon
15° | 17°°C 0 mm 0% 8 mph 65 % 1014 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 16°°C 0 mm 0% 6 mph 71 % 1014 mb 0 mm/h
Tomorrow 4:00 am
weather icon
11° | 13°°C 0 mm 0% 5 mph 77 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
12° | 12°°C 0 mm 0% 9 mph 73 % 1018 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0 mm 0% 8 mph 52 % 1018 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
17° | 17°°C 0 mm 0% 8 mph 36 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
21° | 21°°C 0 mm 0% 7 mph 29 % 1016 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
19° | 19°°C 0 mm 0% 12 mph 40 % 1015 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,664.15
0.42%
Ethereum(ETH)
€2,226.36
-0.50%
Tether(USDT)
€0.88
0.00%
XRP(XRP)
€1.91
-1.27%
Solana(SOL)
€137.21
-1.10%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.169165
-1.09%
Shiba Inu(SHIB)
€0.000011
0.69%
Pepe(PEPE)
€0.000011
-0.17%
Peanut the Squirrel(PNUT)
€0.230892
-0.03%
Scroll to Top