Lazarus窃密币动作活跃,大量资产仍存活

2024-10-15 Threat Book Lazarus Cryptocurrency Theft Activity Remains Active, with Many Assets Still Alive

https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247507123&idx=1&sn=c9291f0c483c9b5d318d48de92ba8987

Thumbnail for Lazarus窃密币动作活跃,大量资产仍存活

Microstep Intelligence says Lazarus continues to target cryptocurrency-related personnel through fake recruiting and research projects posted on LinkedIn, X, Facebook, GitHub, and Stack Overflow. After moving victims into Telegram conversations, the operators lure them into installing trojanized cross-platform projects or fake conferencing software such as FCCCall, including Windows and macOS versions. The analyzed Windows FCCCall MSI uses a Qt6 application and a legitimate-looking video meeting window to hide wallet-data theft, contacts C2 at 185.235.241.208:1224, and uploads browser cryptocurrency wallet extension data. Follow-on Python payloads downloaded from the same infrastructure provide host reconnaissance, file theft, shell execution, clipboard and keylogging functions, process/window monitoring, browser-stealer execution, and AnyDesk-based remote control, showing continued DPRK interest in lightweight JavaScript and Python tooling for crypto theft.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 8ebca0b7ef7dbfc14da3ee39f478e880 2024-08-13 2025-01-20
HASH 5cce14436b3ae5315feec2e12ce6121… 2024-10-15 2024-10-23
HASH 36cac29ff3c503c2123514ea903836d… 2024-09-04 2024-10-23

Related Actors

Related Reports

« Back