구직자의 가상화폐를 노리는 Lazarus 그룹
2024-06-27 • Hauri • Lazarus Group Targets Job Seekers' Cryptocurrency •
https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=64
Attachments
Hauri reports Lazarus activity in which attackers posed as recruiters on LinkedIn and delivered malicious blockchain job-assignment projects through GitHub or Bitbucket to software developers. The NodeJS malware steals cryptocurrency wallets from browser extensions, sends the stolen data with the infected PC name to 23.106.253.209:1244, then downloads Python 3.11 and runs additional Python payloads. The follow-on chain includes a downloader, a browser infostealer that collects saved logins and credit cards from Chrome, Opera, Brave, Yandex, and Edge, and an InvisibleFerret backdoor that gathers host data, contacts 173.211.106.101:1245, and supports keylogging, file theft, remote control, and AnyDesk installation. The report provides repository URLs, C2 paths, and hashes for the JavaScript and Python components.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 173.211.106.101 | 2024-04-25 | 2025-07-26 |
| IPv4 | 23.106.253.209 | 2024-06-27 | 2024-10-23 |
| HASH | eec85de2d612684162d5d1399c53b79b | 2024-06-27 | 2024-06-27 |
| HASH | 1f5bde988fee6fe37092a0eff5c4b479 | 2024-06-27 | 2024-06-27 |
| HASH | 05d4f890c5583efc491a6b4e4534a0de | 2024-06-27 | 2024-06-27 |
| HASH | 09297dbe3cc2cdf2a9f051e2d4ea9948 | 2024-06-27 | 2024-06-27 |
| HASH | 4b473dd7f3e432f4eb10cb4e7ba85a98 | 2024-06-27 | 2024-06-27 |