加密货币 APT 情报:揭秘 Lazarus Group 入侵手法
2025-02-23 • Slowmist • Cryptocurrency APT Intelligence: Revealing Lazarus Group Intrusion Techniques •
SlowMist assessed a state-level APT campaign targeting cryptocurrency exchanges and attributed it to Lazarus Group after forensic analysis and correlation over recent incidents. The attackers used social engineering to persuade employees to run disguised Python projects such as `StockInvestSimulator-main.zip` and `MonteCarloStockInvestSimulator-main.zip`, then abused `pyyaml` `yaml.load` behavior for RCE and malware delivery. The intrusion path described local device compromise, Docker `privileged: true` abuse for privilege escalation, internal scanning, exploitation of enterprise services, SSH key theft, and lateral movement toward wallet servers. Reported infrastructure and identities included `gossipsnare[.]com`, `showmanroast[.]com`, `getstockprice[.]info`, `eclairdomain[.]com`, `replaydreary[.]com`, several GitHub accounts, and Telegram `@tanzimahmed88`. The stated objective was to obtain wallet control and transfer large amounts of cryptocurrency while using legitimate enterprise tools, VPN traffic, and log or sample deletion to obscure activity.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 208.95.112.1 | 2022-11-14 | 2026-01-21 |
| DOMAIN | showmanroast.com | 2025-02-23 | 2025-08-06 |
| DOMAIN | getstockprice.info | 2025-02-23 | 2025-08-06 |
| DOMAIN | gossipsnare.com | 2025-02-23 | 2025-08-06 |
| DOMAIN | coreladao.com | 2025-02-23 | 2025-08-06 |
| DOMAIN | replaydreary.com | 2025-02-23 | 2025-08-06 |
| DOMAIN | cdn.clubinfo.io | 2025-02-23 | 2025-08-06 |
| DOMAIN | eclairdomain.com | 2025-02-23 | 2025-08-06 |
| IPv4 | 131.226.2.120 | 2025-02-23 | 2025-08-06 |
| IPv4 | 51.38.145.49 | 2025-02-23 | 2025-08-06 |
| IPv4 | 37.120.247.180 | 2025-02-23 | 2025-08-06 |
| IPv4 | 88.119.175.208 | 2025-02-23 | 2025-08-06 |
| IPv4 | 193.233.171.58 | 2025-02-23 | 2025-08-06 |
| IPv4 | 193.233.85.234 | 2025-02-23 | 2025-08-06 |
| IPv4 | 213.252.232.171 | 2025-02-23 | 2025-08-06 |
| URL | https://t.zsxq.com/Q3zNvvF | 2025-02-23 | 2025-02-23 |
| DOMAIN | t.zsxq.com | 2025-02-23 | 2025-02-23 |
| IPv4 | 23.195.153.175 | 2025-02-23 | 2025-02-23 |
| IPv4 | 204.79.197.203 | 2019-08-21 | 2025-02-23 |