Hunting Lazarus Part IV: Real Blood on the Wire
2026-02-03 • Red Asgard •
https://redasgard.com/blog/hunting-lazarus-part4-real-blood-on-the-wire
Red Asgard's follow-up investigation into the Contagious Interview campaign found that the suspected C2 infrastructure was operational rather than a honeypot, exposing 241,764 stolen credentials from 857 victims across 90 countries. The victim set centered on software developers and freelancers, especially in South Asia, recruited through fake job interviews on platforms such as Upwork and Fiverr and compromised through malicious project workflows. The exposed data included plaintext banking, payment, cryptocurrency, Google, GitHub, Upwork, and local development credentials, with unauthenticated endpoints serving victim records and browser-data archives. The researchers also identified an AnyDesk RAT that silently installs remote desktop access, steals AnyDesk credentials, injects hardcoded attacker credentials, and gives operators persistent access. The findings matter because they show credential theft, developer compromise, and remote-access persistence at significant scale within a Lazarus-linked Contagious Interview operation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.164.17.24 | 2024-07-15 | 2026-04-01 |
| IPv4 | 87.236.177.9 | 2026-01-23 | 2026-03-17 |
| IPv4 | 147.124.213.232 | 2026-01-12 | 2026-02-26 |
| IPv4 | 216.250.251.87 | 2026-01-12 | 2026-02-26 |
| IPv4 | 45.59.163.55 | 2026-01-12 | 2026-02-26 |
| IPv4 | 66.235.168.238 | 2026-01-12 | 2026-02-15 |
| URL | https://www.paypal.com/signin | 2026-02-03 | 2026-02-03 |
| DOMAIN | elvengold.com | 2026-02-03 | 2026-02-03 |
| DOMAIN | tokenloopz.com | 2026-02-03 | 2026-02-03 |
| DOMAIN | email.tokenloopz.com | 2026-02-03 | 2026-02-03 |
| IPv4 | 172.86.105.40 | 2026-02-01 | 2026-02-03 |
| IPv4 | 147.124.212.125 | 2026-01-12 | 2026-02-03 |
| IPv4 | 144.172.104.117 | 2025-11-26 | 2026-02-03 |
| IPv4 | 172.86.116.178 | 2025-10-21 | 2026-02-03 |
| HASH | e43673a2a77ed68fa6e8074167350f8f | 2025-10-20 | 2026-02-03 |
| HASH | 351535afd2d98b9a3a0e14905a60a345 | 2025-10-20 | 2026-02-03 |
| HASH | 967adedce518105664c46e21fd4edb0… | 2025-10-20 | 2026-02-03 |
| IPv4 | 146.70.253.107 | 2025-10-10 | 2026-02-03 |
| IPv4 | 86.106.85.234 | 2025-10-06 | 2026-02-03 |
| IPv4 | 144.172.101.45 | 2025-06-03 | 2026-02-03 |
| IPv4 | 147.124.214.129 | 2024-05-10 | 2026-02-03 |