Infostealer malware linked to Lazarus Group campaigns
2025-02-07 • Rayssa Cardoso •
https://medium.com/@rayssac/infostealer-malware-linked-to-lazarus-group-campaigns-a510ad5f3e4f
The author analyzes a malicious Python infostealer delivered through a cloned Git repository and compares the pattern to Lazarus Contagious Interview activity against developers. The script uses repeated reversed Base64 and zlib decoding stages before revealing a modular payload that checks the victim operating system, communicates with C2 over port 1224, collects system and geolocation details, and stages data for upload. Additional modules capture clipboard and keystroke logs, inspect Python and browser-related artifacts, and expose backdoor commands such as kill, upload, start, listen, and keep alive. The source links the delivery pattern to ClickFix-style social engineering, where fake errors or developer tasks trick victims into executing commands or code themselves.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| URL | http://ip-api.com/json | 2024-07-31 | 2026-01-20 |
| IPv4 | 5.253.43.122 | 2025-01-29 | 2025-11-13 |
| IPv4 | 95.164.7.171 | 2024-10-14 | 2025-07-26 |
| IPv4 | 41.208.185.235 | 2025-02-07 | 2025-02-07 |
| IPv4 | 91.92.120.132 | 2025-01-29 | 2025-02-07 |