Lazarus関係者?のインフォスティーラー感染ログから見る、攻撃者が利用しているWebサービス

2025-12-10 skybreaker Web Services Used by Attackers as Seen in Infostealer Logs of a Possible Lazarus-Related Actor

https://www.sdsg.moe/entry/2025/12/10/233030

Thumbnail for Lazarus関係者?のインフォスティーラー感染ログから見る、攻撃者が利用しているWebサービス

The Japanese blog examines infostealer logs tied to [email protected] and pivots from saved credentials on that machine to other infected systems and accounts that may be connected to a possible Lazarus-related operator. The excerpt describes compromised Windows hosts in the United States and Finland and notes credentials for services useful in domain registration, hosting, marketing email, SMS and phone numbers, VPNs, residential proxies, identity-document generation, cloud services, Web3 APIs, npm, payment-page builders, tunneling, and remote-control tools. One linked machine is described as containing job-search and recruitment credentials across many regions, with Korean-name artifacts alongside different English personas, suggesting activity consistent with remote-work or identity-based access operations. The author is cautious about attribution, but the exposed service mix is relevant because it maps operational infrastructure and account tooling that could support phishing, impersonation, developer-platform abuse, anonymization, and remote-work positioning.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-02-25 2025-12-16
HASH fb7c07c1d9c6f497434bc35738bb1c6f 2025-12-10 2025-12-10
HASH 854e7feb5d5ad222668e740320127a88 2025-12-10 2025-12-10
HASH 8286398dfb3dba4abeba0c6a975f1733 2025-12-10 2025-12-10
HASH 11b26098d196d30bb12f340a307f00c5 2025-12-10 2025-12-10
HASH e49113011bf68eb495243b964e016fb2 2025-12-10 2025-12-10
HASH f98af3499a2b4e03e1a590dc83435cf7 2025-12-10 2025-12-10
EMAIL [email protected] 2025-12-10 2025-12-10
DOMAIN smscodes.io 2025-12-10 2025-12-10
DOMAIN proxysite.com 2025-12-10 2025-12-10
DOMAIN mobilesms.io 2025-12-10 2025-12-10
DOMAIN infatica.io 2025-12-10 2025-12-10

Related Reports

« Back