Lazarus hackers hijack Microsoft IIS servers to spread malware

Share:

The North Korean state-sponsored Lazarus hacking group is breaching Windows Internet Information Service (IIS) web servers to hijack them for malware distribution.

IIS is Microsoft’s web server solution used to host websites or application services, such as Microsoft Exchange’s Outlook on the Web.

South Korean security analysts at ASEC previously reported that Lazarus was targeting IIS servers for initial access to corporate networks. Today, the cybersecurity company says that the threat group leverages poorly protected IIS services for malware distribution too.

The main advantage of this technique is the ease of infecting visitors of websites or users of services hosted on breached IIS servers owned by trustworthy organizations.

Attacks on South Korea

In the recent attacks observed by ASEC’s analysts, Lazarus compromised legitimate South Korean websites to perform ‘Watering Hole’ attacks on visitors using a vulnerable version of the INISAFE CrossWeb EX V6 software.

Many public and private organizations in South Korea use this particular software for electronic financial transactions, security certification, internet banking, etc.

The INISAFE vulnerability was previously documented by both Symantec and ASEC in 2022, explaining that it was exploited using HTML email attachments at the time.

“A typical attack begins when a malicious HTM file is received, likely as a malicious link in an email or downloaded from the web. The HTM file is copied to a DLL file called scskapplink.dll and injected into the legitimate system management software INISAFE Web EX Client,” explains the 2022 report by Symantec.

Exploiting the flaw fetches a malicious ‘SCSKAppLink.dll’ payload from an IIS web server already compromised before the attack for use as a malware distribution server.

“The download URL for ‘SCSKAppLink.dll’ was identified as being the aforementioned IIS web server,” explains ASEC’s new report.

“This signifies that the threat actor attacked and gained control over IIS web servers before using these as servers for distributing malware.”

ASEC did not analyze the particular payload but says it is likely a malware downloader seen in other recent Lazarus campaigns.

Next, Lazarus uses the ‘JuicyPotato’ privilege escalation malware (‘usopriv.exe’) to gain higher-level access to the compromised system.

Using JuicyPotato in the attacks
JuicyPotato in action (ASEC)

JuicyPotato is used for executing a second malware loader (‘usoshared.dat’) that decrypts downloaded data files and executes them into memory for AV evasion.

Loading the decrypted executable in memory
Loading the decrypted executable in memory (ASEC)

ASEC recommends that NISAFE CrossWeb EX V6 users update the software to its latest version, as Lazarus’ exploitation of known vulnerabilities in the product has been underway since at least April 2022.

The security company advises users to upgrade to version 3.3.2.41 or later and points to remediation instructions it posted four months ago, highlighting the Lazarus threat.

Microsoft application servers are becoming a popular target for hackers to use in malware distribution, likely due to their trusted nature.

Just last week, CERT-UA and Microsoft reported that Russian Turla hackers were using compromised Microsoft Exchange servers to deliver backdoors to their targets.

 

(c) Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:21 pm, May 23, 2025
weather icon 14°C
L: 13° | H: 15°
overcast clouds
Humidity: 64 %
Pressure: 1016 mb
Wind: 11 mph SW
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 87%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:57 am
Sunset: 8:56 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 10:00 pm
weather icon
13° | 15°°C 1 mm 100% 13 mph 98 % 1016 mb 0 mm/h
Sun May 25 10:00 pm
weather icon
13° | 19°°C 0.61 mm 61% 18 mph 90 % 1015 mb 0 mm/h
Mon May 26 10:00 pm
weather icon
10° | 18°°C 0.52 mm 52% 13 mph 79 % 1018 mb 0 mm/h
Tue May 27 10:00 pm
weather icon
13° | 21°°C 1 mm 100% 15 mph 94 % 1017 mb 0 mm/h
Wed May 28 10:00 pm
weather icon
14° | 19°°C 0.25 mm 25% 16 mph 89 % 1022 mb 0 mm/h
Tomorrow 1:00 am
weather icon
13° | 14°°C 0.51 mm 51% 7 mph 71 % 1016 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 12°°C 1 mm 100% 7 mph 87 % 1015 mb 0 mm/h
Tomorrow 7:00 am
weather icon
13° | 13°°C 1 mm 100% 10 mph 98 % 1013 mb 0 mm/h
Tomorrow 10:00 am
weather icon
16° | 16°°C 0.7 mm 70% 10 mph 97 % 1012 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
22° | 22°°C 0.17 mm 17% 13 mph 62 % 1012 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
21° | 21°°C 0 mm 0% 13 mph 60 % 1011 mb 0 mm/h
Tomorrow 7:00 pm
weather icon
19° | 19°°C 0.2 mm 20% 10 mph 76 % 1011 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
16° | 16°°C 0.2 mm 20% 11 mph 90 % 1011 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€95,493.44
-2.38%
Ethereum(ETH)
€2,239.91
-3.69%
Tether(USDT)
€0.88
-0.01%
XRP(XRP)
€2.05
-3.62%
Solana(SOL)
€156.37
-0.41%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.203834
-3.33%
Shiba Inu(SHIB)
€0.000013
-3.92%
Pepe(PEPE)
€0.000013
2.59%
Peanut the Squirrel(PNUT)
€0.307670
-2.29%
Scroll to Top