Hunting Lazarus, Part 5: Eleven Hours on His Disk

2026-02-28 Red Asgard

https://redasgard.com/blog/hunting-lazarus-part5-eleven-hours-on-his-disk

Thumbnail for Hunting Lazarus, Part 5: Eleven Hours on His Disk

Red Asgard examined an active Lazarus Group operator VPS tied to the Contagious Interview campaign, which targets cryptocurrency and Web3 developers through fake job interviews, fabricated company identities, and malicious repositories. The Windows Server 2025 host WIN-RCH83RTDA5G on MonoVM preserved intact event logs, registry hives, and prefetch artifacts, allowing investigators to reconstruct operator access rather than infer activity only from external telemetry. A confirmed RDP logon at 06:13:44 UTC on February 19 came from 37.19.200.137, a DataCamp/CDNEXT-DAL VPN exit node, after investigators had accessed the disk through provider rescue mode. The disk reportedly exposed operational material including a target list of nearly 17,000 developers, six drained wallets, and a plaintext file containing the operator's own keys, making it a rare view into Lazarus infrastructure and tradecraft.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 195.201.104.53 2026-02-28 2026-04-22
IPv4 216.126.227.239 2026-02-28 2026-04-02
DOMAIN tunebook.io 2026-02-28 2026-02-28
IPv4 37.19.200.137 2026-02-28 2026-02-28
IPv4 167.88.165.222 2026-02-28 2026-02-28
IPv4 144.172.89.198 2026-02-28 2026-02-28
IPv4 23.227.199.7 2026-02-28 2026-02-28
IPv4 62.33.223.164 2026-02-22 2026-02-28
IPv4 67.43.49.10 2026-01-21 2026-02-28

Related Actors

Related Reports

« Back