북한 Lazarus(라자루스) 가상화폐(암호화폐)탈취를 위해 만들어진 악성코드-config(.)py(2025.8.7)

2025-09-29 Sakai North Korea/Lazarus cyber threat report

https://wezard4u.tistory.com/429606

Thumbnail for 북한 Lazarus(라자루스) 가상화폐(암호화폐)탈취를 위해 만들어진 악성코드-config(.)py(2025.8.7)

A Korean analysis attributes a Python malware file named config.py to Lazarus activity focused on cryptocurrency theft. The script is designed to collect Chrome and Chromium browser profile data, including cryptocurrency wallet extension storage, cookies, keys, login data, Local Storage, IndexedDB, and related extension files. It targets wallet extensions such as MetaMask, Phantom, Coinbase Wallet, Keplr, and Rabby, then sends data to a hard-coded HTTP C2 at 151.243.101.229:8080. Persistence is established through the HKCU Run key named csshost, and the malware stores host data in files such as .host and .store while beaconing every 20 to 40 seconds. The command protocol uses short tokens for functions such as ping, upload, download, shell access, and automated Chrome collection, making the sample relevant to defenders tracking DPRK cryptocurrency-stealing tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 151.243.101.229 2025-08-06 2026-01-21
HASH ef9c744288d17f53d85f9fbeeea587e2 2025-09-29 2025-09-29
HASH 70132499c4b5a0cad01a261758036e5… 2025-09-29 2025-09-29
HASH c7ecf8be40c1e9a9a8c3d148eb2ae2c… 2025-08-06 2025-09-29

Related Actors

Related Reports

« Back