북한 Lazarus(라자루스) 가상화폐(암호화폐)탈취를 위해 만들어진 악성코드-config(.)py(2025.8.7)
2025-09-29 • Sakai • North Korea/Lazarus cyber threat report •
A Korean analysis attributes a Python malware file named config.py to Lazarus activity focused on cryptocurrency theft. The script is designed to collect Chrome and Chromium browser profile data, including cryptocurrency wallet extension storage, cookies, keys, login data, Local Storage, IndexedDB, and related extension files. It targets wallet extensions such as MetaMask, Phantom, Coinbase Wallet, Keplr, and Rabby, then sends data to a hard-coded HTTP C2 at 151.243.101.229:8080. Persistence is established through the HKCU Run key named csshost, and the malware stores host data in files such as .host and .store while beaconing every 20 to 40 seconds. The command protocol uses short tokens for functions such as ping, upload, download, shell access, and automated Chrome collection, making the sample relevant to defenders tracking DPRK cryptocurrency-stealing tradecraft.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 151.243.101.229 | 2025-08-06 | 2026-01-21 |
| HASH | ef9c744288d17f53d85f9fbeeea587e2 | 2025-09-29 | 2025-09-29 |
| HASH | 70132499c4b5a0cad01a261758036e5… | 2025-09-29 | 2025-09-29 |
| HASH | c7ecf8be40c1e9a9a8c3d148eb2ae2c… | 2025-08-06 | 2025-09-29 |