PULSE NAME
Lojack Becomes a Double-Agent
WHITE Sofacy AlienVault 2018-05-01 Modified: 2018-06-07
20
IOCs
MEDIUM VOLUME
ASERT recently discovered Lojack agents containing malicious C2s. These hijacked agents pointed to suspected Fancy Bear (a.k.a. APT28, Pawn Storm) domains. The InfoSec community and the U.S. government have both attributed Fancy Bear activity to Russian espionage activity. Fancy Bear actors typically choose geopolitical targets, such as governments and international organizations. They also target industries that do business with such organizations, such as defense contractors. Lojack, formally known as Computrace, is a legitimate laptop recovery solution used by a number of companies to protect their assets should they be stolen. Lojack makes an excellent double-agent due to appearing as legit software while natively allowing remote code execution. Although the initial intrusion vector for this activity remains unknown, Fancy Bear often utilizes phishing email to deliver payloads.
Indicators of Compromise (20)
All YARA domain FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
YARA e7d2c356ca95b29a7d0f4acd455ca12ad0dc1d10 2018-05-01
domain elaxo.org 2018-05-01
domain ikmtrust.com 2018-05-01
domain lxwo.org 2018-05-01
domain sysanalyticweb.com 2018-05-01
FileHash-MD5 5b3968b47eb16a1cb88525e3b565eab1 2018-05-01
FileHash-MD5 6eaa1ff5f33df3169c209f98cc5012d0 2018-05-01
FileHash-MD5 ac1a85d3ca1b6265cad4ed41b696f9b7 2018-05-01
FileHash-MD5 cf45ec807321d12f8df35fa434591460 2018-05-01
FileHash-MD5 e78e3b0171b189074d2539c7baaa0719 2018-05-01
FileHash-MD5 f1df1a795eb784f7bfc3ba9a7e3b00ac 2018-05-01
FileHash-MD5 f391556d9f89499fa8ee757cb3472710 2018-05-01
FileHash-MD5 f3c6e16f0dd2b0e55a7dad365c3877d4 2018-05-01
domain webstp.com 2018-06-07
FileHash-SHA1 09d2e2c26247a4a908952fee36b56b360561984f 2018-06-07
FileHash-SHA1 10d571d66d3ab7b9ddf6a850cb9b8e38b07623c0 2018-06-07
FileHash-SHA1 1470995de2278ae79646d524e7c311dad29aee17 2018-06-07
FileHash-SHA1 2529f6eda28d54490119d2123d22da56783c704f 2018-06-07
FileHash-SHA1 397d97e278110a48bd2cb11bb5632b99a9100dbd 2018-06-07
FileHash-SHA1 ddaa06a4021baf980a08caea899f2904609410b9 2018-06-07