Lazarus Group Targets Blockchain Developers with Social Engineering and Visual Deception Techniques in Code

2024-05-13 Dimitribest

https://www.linkedin.com/pulse/lazarus-group-targets-blockchain-developers-social-visual-bestuzhev-ije9e/

Thumbnail for Lazarus Group Targets Blockchain Developers with Social Engineering and Visual Deception Techniques in Code

Lazarus Group is described targeting full-stack Web3 and blockchain developers, especially people advertising job availability and exposed contact details on GitHub. The campaign uses social engineering lures such as job offers or collaboration requests to push victims into cloning trojanized GitHub projects that appear relevant to blockchain, NFT, ERP/CRM, or React development work. Malicious obfuscated JavaScript is hidden in files such as address.js, Treasury.js, appApi.js, and entryRoutes.js, sometimes beyond long legitimate lines or inside comments to exploit code editors with line wrapping disabled. The implants communicate with multiple C2 servers including 147.124.214.131:1244, 147.124.214.237:1244, 67.203.7.171:1244, and 147.124.212.89:1244, creating risk of system compromise, project access, cryptocurrency theft, and exposure of sensitive development data.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 147.124.214.237 2024-05-10 2026-01-21
IPv4 147.124.214.131 2024-04-25 2026-01-21
IPv4 67.203.7.171 2024-05-10 2025-11-13
IPv4 147.124.212.89 2023-12-12 2025-11-13
HASH e340a51be18a3a0736be11d8335e8e6… 2024-05-13 2024-05-13
HASH 494862e37bbf509cc0ec3865f0a8926… 2024-05-13 2024-05-13
HASH fdfe98d511bce7630de9b2688d315d2… 2024-05-13 2024-05-13
HASH f9eb197c25d5e3158edd274013c56ec… 2024-05-13 2024-05-13
HASH 61e93e0fa6ea4713dd68d9d8b40a681… 2024-05-13 2024-05-13
HASH f89658839174089720f0841dec8c25e… 2024-05-13 2024-05-13
HASH 80088a571cca8967c1bbf84e1afb3aa… 2024-05-13 2024-05-13

Related Actors

Related Reports

« Back