Hunting Lazarus Part II: When the Dead Drop Moved to the Blockchain

2026-01-23 Red Asgard

https://redasgard.com/blog/hunting-lazarus-part2-blockchain-dead-drop

Thumbnail for Hunting Lazarus Part II: When the Dead Drop Moved to the Blockchain

Red Asgard links a new Contagious Interview sample to Lazarus Group and reports a shift from Pastebin dead drops to Polygon NFT contracts used as a blockchain-based dead drop resolver. The campaign impersonated the real cryptocurrency betting company Betfin, using LinkedIn outreach, voice-only interview calls, private code repositories, and pressure to clone and run a project during the interview. The infection chain abused VSCode folder-open tasks and npm script hijacking to run Node.js malware, query Polygon RPC endpoints, execute fetched JavaScript with full Node.js capabilities, and deploy a RAT and stealer. Captured payloads targeted cryptocurrency wallets, password managers, browsers, and developer credentials, with infrastructure including 87.236.177.9:3000 and Polygon contract addresses 0xad031E8d8877481337cD53E141C16A2201BB6F4d and 0xa80db78ff597c3D34cCAF3bdaC39f3E193595561. The report matters because blockchain-hosted payload configuration is resistant to takedown and blends into legitimate Web3 traffic.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN polygon-rpc.com 2025-02-26 2026-04-29
IPv4 87.236.177.9 2026-01-23 2026-03-17
IPv4 147.124.213.232 2026-01-12 2026-02-26
IPv4 45.59.163.55 2026-01-12 2026-02-26
IPv4 66.235.168.238 2026-01-12 2026-02-15
IPv4 147.124.212.125 2026-01-12 2026-02-03
HASH 3e2d9bcf6ff5ae441493df87e8c46b6… 2026-01-23 2026-01-23
HASH 43223ce324e65b694bb8dd6bbf7992e… 2026-01-23 2026-01-23
HASH e695f6628abade062d5a2310e16c5b2… 2026-01-23 2026-01-23
IPv4 11.34.242.92 2026-01-23 2026-01-23

Related Actors

Related Reports

« Back