Lazarus Group Targets Blockchain Developers with Social Engineering and Visual Deception Techniques in Code
2024-05-13 • Dimitribest •
Lazarus Group is described targeting full-stack Web3 and blockchain developers, especially people advertising job availability and exposed contact details on GitHub. The campaign uses social engineering lures such as job offers or collaboration requests to push victims into cloning trojanized GitHub projects that appear relevant to blockchain, NFT, ERP/CRM, or React development work. Malicious obfuscated JavaScript is hidden in files such as address.js, Treasury.js, appApi.js, and entryRoutes.js, sometimes beyond long legitimate lines or inside comments to exploit code editors with line wrapping disabled. The implants communicate with multiple C2 servers including 147.124.214.131:1244, 147.124.214.237:1244, 67.203.7.171:1244, and 147.124.212.89:1244, creating risk of system compromise, project access, cryptocurrency theft, and exposure of sensitive development data.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 147.124.214.237 | 2024-05-10 | 2026-01-21 |
| IPv4 | 147.124.214.131 | 2024-04-25 | 2026-01-21 |
| IPv4 | 67.203.7.171 | 2024-05-10 | 2025-11-13 |
| IPv4 | 147.124.212.89 | 2023-12-12 | 2025-11-13 |
| HASH | e340a51be18a3a0736be11d8335e8e6… | 2024-05-13 | 2024-05-13 |
| HASH | 494862e37bbf509cc0ec3865f0a8926… | 2024-05-13 | 2024-05-13 |
| HASH | fdfe98d511bce7630de9b2688d315d2… | 2024-05-13 | 2024-05-13 |
| HASH | f9eb197c25d5e3158edd274013c56ec… | 2024-05-13 | 2024-05-13 |
| HASH | 61e93e0fa6ea4713dd68d9d8b40a681… | 2024-05-13 | 2024-05-13 |
| HASH | f89658839174089720f0841dec8c25e… | 2024-05-13 | 2024-05-13 |
| HASH | 80088a571cca8967c1bbf84e1afb3aa… | 2024-05-13 | 2024-05-13 |