Hunting Lazarus Part II: When the Dead Drop Moved to the Blockchain
2026-01-23 • Red Asgard •
https://redasgard.com/blog/hunting-lazarus-part2-blockchain-dead-drop
Red Asgard links a new Contagious Interview sample to Lazarus Group and reports a shift from Pastebin dead drops to Polygon NFT contracts used as a blockchain-based dead drop resolver. The campaign impersonated the real cryptocurrency betting company Betfin, using LinkedIn outreach, voice-only interview calls, private code repositories, and pressure to clone and run a project during the interview. The infection chain abused VSCode folder-open tasks and npm script hijacking to run Node.js malware, query Polygon RPC endpoints, execute fetched JavaScript with full Node.js capabilities, and deploy a RAT and stealer. Captured payloads targeted cryptocurrency wallets, password managers, browsers, and developer credentials, with infrastructure including 87.236.177.9:3000 and Polygon contract addresses 0xad031E8d8877481337cD53E141C16A2201BB6F4d and 0xa80db78ff597c3D34cCAF3bdaC39f3E193595561. The report matters because blockchain-hosted payload configuration is resistant to takedown and blends into legitimate Web3 traffic.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | polygon-rpc.com | 2025-02-26 | 2026-04-29 |
| IPv4 | 87.236.177.9 | 2026-01-23 | 2026-03-17 |
| IPv4 | 147.124.213.232 | 2026-01-12 | 2026-02-26 |
| IPv4 | 45.59.163.55 | 2026-01-12 | 2026-02-26 |
| IPv4 | 66.235.168.238 | 2026-01-12 | 2026-02-15 |
| IPv4 | 147.124.212.125 | 2026-01-12 | 2026-02-03 |
| HASH | 3e2d9bcf6ff5ae441493df87e8c46b6… | 2026-01-23 | 2026-01-23 |
| HASH | 43223ce324e65b694bb8dd6bbf7992e… | 2026-01-23 | 2026-01-23 |
| HASH | e695f6628abade062d5a2310e16c5b2… | 2026-01-23 | 2026-01-23 |
| IPv4 | 11.34.242.92 | 2026-01-23 | 2026-01-23 |