Beyond the Pond Phish: Unraveling Lazarus Group’s Evolving Tactics
2025-05-30 • Bitmex •
BitMEX analyzed a Lazarus Group campaign targeting cryptocurrency-sector personnel through LinkedIn outreach and a private GitHub repository for a supposed NFT marketplace collaboration. The repository contained a Next.js/React project with JavaScript that contacted regioncheck[.]net and fashdefi[.]store:6168, executed returned code, and exposed strings consistent with credential-stealing behavior associated with BeaverTail-style DPRK malware. Deobfuscation showed the first-stage code writing infected host metadata to a misconfigured Supabase database, including username, hostname, OS, IP address, geolocation, and timestamp. That exposed database contained hundreds of infection logs and apparent operator test systems, including VPN-heavy activity and a China Mobile IP address that BitMEX assessed as an operational security mistake. The case highlights a gap between relatively simple Lazarus social engineering for initial access and more capable post-exploitation operations against crypto targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 199.168.113.31 | 2025-05-30 | 2026-01-21 |
| IPv4 | 195.146.5.31 | 2025-05-30 | 2026-01-21 |
| IPv4 | 89.187.185.11 | 2025-05-30 | 2026-01-21 |
| IPv4 | 167.88.61.148 | 2025-05-30 | 2026-01-21 |
| IPv4 | 89.187.161.220 | 2025-05-30 | 2026-01-21 |
| IPv4 | 129.232.193.253 | 2025-05-30 | 2026-01-21 |
| IPv4 | 38.170.181.10 | 2025-01-26 | 2026-01-21 |
| IPv4 | 144.172.96.35 | 2025-05-30 | 2025-10-16 |
| URL | https://mkswbddldpyiqkyu.supaba… | 2025-05-30 | 2025-05-30 |
| DOMAIN | mkswbddldpyiqkyu.supabase.co | 2025-05-30 | 2025-05-30 |
| IPv4 | 108.181.57.127 | 2025-05-30 | 2025-05-30 |
| IPv4 | 107.182.231.193 | 2025-05-30 | 2025-05-30 |
| IPv4 | 31.13.189.26 | 2025-05-30 | 2025-05-30 |
| IPv4 | 217.138.198.34 | 2025-05-30 | 2025-05-30 |
| IPv4 | 89.116.158.84 | 2025-05-30 | 2025-05-30 |
| IPv4 | 45.141.153.154 | 2025-05-30 | 2025-05-30 |
| IPv4 | 37.120.216.226 | 2025-05-30 | 2025-05-30 |
| IPv4 | 223.104.144.97 | 2025-05-30 | 2025-05-30 |
| IPv4 | 45.56.197.79 | 2025-05-30 | 2025-05-30 |
| IPv4 | 38.132.106.130 | 2025-05-30 | 2025-05-30 |
| IPv4 | 89.116.158.228 | 2025-05-30 | 2025-05-30 |
| IPv4 | 89.116.158.68 | 2025-05-30 | 2025-05-30 |
| IPv4 | 31.13.189.178 | 2025-05-30 | 2025-05-30 |
| IPv4 | 120.226.22.28 | 2025-05-30 | 2025-05-30 |
| IPv4 | 38.134.148.94 | 2025-05-30 | 2025-05-30 |
| IPv4 | 184.174.5.149 | 2025-05-30 | 2025-05-30 |
| IPv4 | 89.116.158.156 | 2025-05-30 | 2025-05-30 |
| IPv4 | 31.13.189.10 | 2025-05-30 | 2025-05-30 |
| IPv4 | 107.182.231.196 | 2025-05-30 | 2025-05-30 |
| IPv4 | 45.141.153.130 | 2025-05-30 | 2025-05-30 |
| IPv4 | 89.116.158.188 | 2025-05-30 | 2025-05-30 |
| IPv4 | 146.70.63.2 | 2025-05-30 | 2025-05-30 |
| IPv4 | 89.116.158.164 | 2025-05-30 | 2025-05-30 |
| IPv4 | 209.127.117.234 | 2025-02-25 | 2025-05-30 |
| DOMAIN | regioncheck.net | 2024-09-04 | 2025-05-30 |