Infostealer malware linked to Lazarus Group campaigns

2025-02-07 Rayssa Cardoso

https://medium.com/@rayssac/infostealer-malware-linked-to-lazarus-group-campaigns-a510ad5f3e4f

The author analyzes a malicious Python infostealer delivered through a cloned Git repository and compares the pattern to Lazarus Contagious Interview activity against developers. The script uses repeated reversed Base64 and zlib decoding stages before revealing a modular payload that checks the victim operating system, communicates with C2 over port 1224, collects system and geolocation details, and stages data for upload. Additional modules capture clipboard and keystroke logs, inspect Python and browser-related artifacts, and expose backdoor commands such as kill, upload, start, listen, and keep alive. The source links the delivery pattern to ClickFix-style social engineering, where fake errors or developer tasks trick victims into executing commands or code themselves.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ip-api.com 2022-11-14 2026-01-21
URL http://ip-api.com/json 2024-07-31 2026-01-20
IPv4 5.253.43.122 2025-01-29 2025-11-13
IPv4 95.164.7.171 2024-10-14 2025-07-26
IPv4 41.208.185.235 2025-02-07 2025-02-07
IPv4 91.92.120.132 2025-01-29 2025-02-07

Related Actors

Related Reports

2025-02-20 • 51% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: T1082, T1041, T1056.001 • Shares 2 IOCs • Published within a month
« Back