Hunting Lazarus Part VII: The Server That Was Not Just FTP

2026-05-06 Red Asgard

https://redasgard.com/blog/hunting-lazarus-part7-server-not-just-ftp

Thumbnail for Hunting Lazarus Part VII: The Server That Was Not Just FTP

Red Asgard ties the Hetzner host at 195.201.104.53 to more than BeaverTail FTP exfiltration, showing it also exposed six Express.js services on non-standard ports. Port 21 ran FileZilla Server 1.12.1 with TLS session resumption enforced and held seventy victim folders under team-numbered prefixes. Two Express services mapped to OtterCookie command-and-control, including one live node broadcasting macOS victim state and a silent predecessor still listening. Port 80 repeatedly leaked a Windows development path from a Linux deployment, indicating shared operational infrastructure across campaigns and malware families.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 195.201.104.53 2026-02-28 2026-04-22

Related Actors

Related Reports

« Back