Lazarus Group Targets Crypto-Wallets and Financial Data while employing new Tradecrafts
2025-05-27 • Alessio Di Santo •
An arXiv paper analyzes a malware sample attributed in the title to Lazarus Group activity targeting crypto-wallets and financial data. Static and dynamic analysis identified persistence mechanisms, command-and-control communication, data exfiltration routines, and supporting infrastructure. The abstract says the sample was correlated with indicators of compromise and known TTPs to assess the likely actor’s capabilities and motivations. The report frames the findings as hunting and detection material for identifying latent compromise and improving alert logic against advanced persistent threats.
Related Actors
Related Reports
Shares tags: BeaverTail, InvisibleFerret, Lazarus
2025-02-04 •
65% Match
#macOS
#BeaverTail
#InvisibleFerret
#Lazarus
#OtterCookie
#FlexibleFerret
#FriendlyFerret
Shares tags: BeaverTail, InvisibleFerret, Lazarus
2026-05-14 •
60% Match
#NPM
#ContagiousInterview
#BeaverTail
#InvisibleFerret
#Lazarus
#VSCode
#Axios
#TasksJacker
Shares tags: BeaverTail, InvisibleFerret, Lazarus
Shares tags: BeaverTail, InvisibleFerret, Lazarus
2024-09-04 •
60% Match
#ContagiousInterview
#BeaverTail
#InvisibleFerret
#MiroTalk
#Lazarus
#CivetQ
#FCCCall
Shares tags: BeaverTail, InvisibleFerret, Lazarus
2025-04-04 •
56% Match
Lazarus Expands Malicious npm Campaign: 11 New Packages Add Malware Loaders and Bitbucket Payloads
Socket
Shares tags: BeaverTail, Lazarus