Beyond the Pond Phish: Unraveling Lazarus Group’s Evolving Tactics

2025-05-30 Bitmex

https://blog.bitmex.com/bitmex-busts-lazarus-group/

Thumbnail for Beyond the Pond Phish: Unraveling Lazarus Group’s Evolving Tactics

BitMEX analyzed a Lazarus Group campaign targeting cryptocurrency-sector personnel through LinkedIn outreach and a private GitHub repository for a supposed NFT marketplace collaboration. The repository contained a Next.js/React project with JavaScript that contacted regioncheck[.]net and fashdefi[.]store:6168, executed returned code, and exposed strings consistent with credential-stealing behavior associated with BeaverTail-style DPRK malware. Deobfuscation showed the first-stage code writing infected host metadata to a misconfigured Supabase database, including username, hostname, OS, IP address, geolocation, and timestamp. That exposed database contained hundreds of infection logs and apparent operator test systems, including VPN-heavy activity and a China Mobile IP address that BitMEX assessed as an operational security mistake. The case highlights a gap between relatively simple Lazarus social engineering for initial access and more capable post-exploitation operations against crypto targets.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 199.168.113.31 2025-05-30 2026-01-21
IPv4 195.146.5.31 2025-05-30 2026-01-21
IPv4 89.187.185.11 2025-05-30 2026-01-21
IPv4 167.88.61.148 2025-05-30 2026-01-21
IPv4 89.187.161.220 2025-05-30 2026-01-21
IPv4 129.232.193.253 2025-05-30 2026-01-21
IPv4 38.170.181.10 2025-01-26 2026-01-21
IPv4 144.172.96.35 2025-05-30 2025-10-16
URL https://mkswbddldpyiqkyu.supaba… 2025-05-30 2025-05-30
DOMAIN mkswbddldpyiqkyu.supabase.co 2025-05-30 2025-05-30
IPv4 108.181.57.127 2025-05-30 2025-05-30
IPv4 107.182.231.193 2025-05-30 2025-05-30
IPv4 31.13.189.26 2025-05-30 2025-05-30
IPv4 217.138.198.34 2025-05-30 2025-05-30
IPv4 89.116.158.84 2025-05-30 2025-05-30
IPv4 45.141.153.154 2025-05-30 2025-05-30
IPv4 37.120.216.226 2025-05-30 2025-05-30
IPv4 223.104.144.97 2025-05-30 2025-05-30
IPv4 45.56.197.79 2025-05-30 2025-05-30
IPv4 38.132.106.130 2025-05-30 2025-05-30
IPv4 89.116.158.228 2025-05-30 2025-05-30
IPv4 89.116.158.68 2025-05-30 2025-05-30
IPv4 31.13.189.178 2025-05-30 2025-05-30
IPv4 120.226.22.28 2025-05-30 2025-05-30
IPv4 38.134.148.94 2025-05-30 2025-05-30
IPv4 184.174.5.149 2025-05-30 2025-05-30
IPv4 89.116.158.156 2025-05-30 2025-05-30
IPv4 31.13.189.10 2025-05-30 2025-05-30
IPv4 107.182.231.196 2025-05-30 2025-05-30
IPv4 45.141.153.130 2025-05-30 2025-05-30
IPv4 89.116.158.188 2025-05-30 2025-05-30
IPv4 146.70.63.2 2025-05-30 2025-05-30
IPv4 89.116.158.164 2025-05-30 2025-05-30
IPv4 209.127.117.234 2025-02-25 2025-05-30
DOMAIN regioncheck.net 2024-09-04 2025-05-30

Related Actors

Related Reports

« Back