Hunting Lazarus Part IV: Real Blood on the Wire

2026-02-03 Red Asgard

https://redasgard.com/blog/hunting-lazarus-part4-real-blood-on-the-wire

Thumbnail for Hunting Lazarus Part IV: Real Blood on the Wire

Red Asgard's follow-up investigation into the Contagious Interview campaign found that the suspected C2 infrastructure was operational rather than a honeypot, exposing 241,764 stolen credentials from 857 victims across 90 countries. The victim set centered on software developers and freelancers, especially in South Asia, recruited through fake job interviews on platforms such as Upwork and Fiverr and compromised through malicious project workflows. The exposed data included plaintext banking, payment, cryptocurrency, Google, GitHub, Upwork, and local development credentials, with unauthenticated endpoints serving victim records and browser-data archives. The researchers also identified an AnyDesk RAT that silently installs remote desktop access, steals AnyDesk credentials, injects hardcoded attacker credentials, and gives operators persistent access. The findings matter because they show credential theft, developer compromise, and remote-access persistence at significant scale within a Lazarus-linked Contagious Interview operation.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.164.17.24 2024-07-15 2026-04-01
IPv4 87.236.177.9 2026-01-23 2026-03-17
IPv4 147.124.213.232 2026-01-12 2026-02-26
IPv4 216.250.251.87 2026-01-12 2026-02-26
IPv4 45.59.163.55 2026-01-12 2026-02-26
IPv4 66.235.168.238 2026-01-12 2026-02-15
URL https://www.paypal.com/signin 2026-02-03 2026-02-03
DOMAIN elvengold.com 2026-02-03 2026-02-03
DOMAIN tokenloopz.com 2026-02-03 2026-02-03
DOMAIN email.tokenloopz.com 2026-02-03 2026-02-03
IPv4 172.86.105.40 2026-02-01 2026-02-03
IPv4 147.124.212.125 2026-01-12 2026-02-03
IPv4 144.172.104.117 2025-11-26 2026-02-03
IPv4 172.86.116.178 2025-10-21 2026-02-03
HASH e43673a2a77ed68fa6e8074167350f8f 2025-10-20 2026-02-03
HASH 351535afd2d98b9a3a0e14905a60a345 2025-10-20 2026-02-03
HASH 967adedce518105664c46e21fd4edb0… 2025-10-20 2026-02-03
IPv4 146.70.253.107 2025-10-10 2026-02-03
IPv4 86.106.85.234 2025-10-06 2026-02-03
IPv4 144.172.101.45 2025-06-03 2026-02-03
IPv4 147.124.214.129 2024-05-10 2026-02-03

Related Actors

Related Reports

« Back