구직자의 가상화폐를 노리는 Lazarus 그룹

2024-06-27 Hauri Lazarus Group Targets Job Seekers' Cryptocurrency

https://download.hauri.net/DownSource/down/dwn_detail_down.html?uid=64

Attachments

2024-06-27ììëìë³ê³ìêµìììêìííìêìëëëLazarusêë¹.pdf (886 KB)

Hauri reports Lazarus activity in which attackers posed as recruiters on LinkedIn and delivered malicious blockchain job-assignment projects through GitHub or Bitbucket to software developers. The NodeJS malware steals cryptocurrency wallets from browser extensions, sends the stolen data with the infected PC name to 23.106.253.209:1244, then downloads Python 3.11 and runs additional Python payloads. The follow-on chain includes a downloader, a browser infostealer that collects saved logins and credit cards from Chrome, Opera, Brave, Yandex, and Edge, and an InvisibleFerret backdoor that gathers host data, contacts 173.211.106.101:1245, and supports keylogging, file theft, remote control, and AnyDesk installation. The report provides repository URLs, C2 paths, and hashes for the JavaScript and Python components.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 173.211.106.101 2024-04-25 2025-07-26
IPv4 23.106.253.209 2024-06-27 2024-10-23
HASH eec85de2d612684162d5d1399c53b79b 2024-06-27 2024-06-27
HASH 1f5bde988fee6fe37092a0eff5c4b479 2024-06-27 2024-06-27
HASH 05d4f890c5583efc491a6b4e4534a0de 2024-06-27 2024-06-27
HASH 09297dbe3cc2cdf2a9f051e2d4ea9948 2024-06-27 2024-06-27
HASH 4b473dd7f3e432f4eb10cb4e7ba85a98 2024-06-27 2024-06-27

Related Actors

Related Reports

« Back