加密货币 APT 情报:揭秘 Lazarus Group 入侵手法

2025-02-23 Slowmist Cryptocurrency APT Intelligence: Revealing Lazarus Group Intrusion Techniques

https://mp.weixin.qq.com/s/rB4XeIBATAb1zHZ9WVyxAg

Thumbnail for 加密货币 APT 情报:揭秘 Lazarus Group 入侵手法

SlowMist assessed a state-level APT campaign targeting cryptocurrency exchanges and attributed it to Lazarus Group after forensic analysis and correlation over recent incidents. The attackers used social engineering to persuade employees to run disguised Python projects such as `StockInvestSimulator-main.zip` and `MonteCarloStockInvestSimulator-main.zip`, then abused `pyyaml` `yaml.load` behavior for RCE and malware delivery. The intrusion path described local device compromise, Docker `privileged: true` abuse for privilege escalation, internal scanning, exploitation of enterprise services, SSH key theft, and lateral movement toward wallet servers. Reported infrastructure and identities included `gossipsnare[.]com`, `showmanroast[.]com`, `getstockprice[.]info`, `eclairdomain[.]com`, `replaydreary[.]com`, several GitHub accounts, and Telegram `@tanzimahmed88`. The stated objective was to obtain wallet control and transfer large amounts of cryptocurrency while using legitimate enterprise tools, VPN traffic, and log or sample deletion to obscure activity.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 208.95.112.1 2022-11-14 2026-01-21
DOMAIN showmanroast.com 2025-02-23 2025-08-06
DOMAIN getstockprice.info 2025-02-23 2025-08-06
DOMAIN gossipsnare.com 2025-02-23 2025-08-06
DOMAIN coreladao.com 2025-02-23 2025-08-06
DOMAIN replaydreary.com 2025-02-23 2025-08-06
DOMAIN cdn.clubinfo.io 2025-02-23 2025-08-06
DOMAIN eclairdomain.com 2025-02-23 2025-08-06
IPv4 131.226.2.120 2025-02-23 2025-08-06
IPv4 51.38.145.49 2025-02-23 2025-08-06
IPv4 37.120.247.180 2025-02-23 2025-08-06
IPv4 88.119.175.208 2025-02-23 2025-08-06
IPv4 193.233.171.58 2025-02-23 2025-08-06
IPv4 193.233.85.234 2025-02-23 2025-08-06
IPv4 213.252.232.171 2025-02-23 2025-08-06
URL https://t.zsxq.com/Q3zNvvF 2025-02-23 2025-02-23
DOMAIN t.zsxq.com 2025-02-23 2025-02-23
IPv4 23.195.153.175 2025-02-23 2025-02-23
IPv4 204.79.197.203 2019-08-21 2025-02-23

Related Actors

Related Reports

« Back