Operation Phantom Circuit: North Korea's Global Data Exfiltration Campaign
2025-01-29 • Security Scorecard •
Attachments
SecurityScorecard describes Operation Phantom Circuit as a Lazarus Group campaign that embedded malware in trusted development tools to compromise cryptocurrency and technology developers worldwide. The infrastructure used C2 servers active from late 2024 into January 2025, a hidden administrative platform, spoofed domains, VPN and proxy routing through Hasan, Russia, and Dropbox for exfiltrated data storage. STRIKE reported more than 1,500 compromised systems across three waves, with stolen development credentials, authentication tokens, browser passwords, and system information collected from victims.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.128.52.14 | 2025-01-29 | 2025-11-13 |
| IPv4 | 185.153.182.241 | 2025-01-29 | 2025-11-13 |
| IPv4 | 5.253.43.122 | 2025-01-29 | 2025-11-13 |
| IPv4 | 86.104.74.51 | 2024-12-03 | 2025-11-13 |
| IPv4 | 94.131.9.32 | 2025-01-29 | 2025-05-13 |
| DOMAIN | sageskills-uk.com | 2025-01-29 | 2025-01-29 |
| DOMAIN | skillsage.uk | 2025-01-29 | 2025-01-29 |
| IPv4 | 204.188.233.68 | 2025-01-29 | 2025-01-29 |
| IPv4 | 70.39.70.196 | 2025-01-29 | 2025-01-29 |
| IPv4 | 175.45.178.130 | 2025-01-29 | 2025-01-29 |
| IPv4 | 83.234.227.53 | 2025-01-29 | 2025-01-29 |
| IPv4 | 175.45.178.9 | 2025-01-29 | 2025-01-29 |
| IPv4 | 83.234.227.52 | 2025-01-29 | 2025-01-29 |
| IPv4 | 175.45.178.11 | 2025-01-29 | 2025-01-29 |
| IPv4 | 83.234.227.49 | 2025-01-29 | 2025-01-29 |
| IPv4 | 70.39.70.197 | 2025-01-29 | 2025-01-29 |
| IPv4 | 83.234.227.51 | 2025-01-29 | 2025-01-29 |
| IPv4 | 83.234.227.50 | 2025-01-29 | 2025-01-29 |
| IPv4 | 45.58.143.196 | 2025-01-29 | 2025-01-29 |
| IPv4 | 199.115.99.62 | 2025-01-29 | 2025-01-29 |
| IPv4 | 175.45.178.10 | 2025-01-29 | 2025-01-29 |
| IPv4 | 175.45.178.14 | 2025-01-29 | 2025-01-29 |
| IPv4 | 175.45.176.27 | 2023-02-02 | 2025-01-29 |
| IPv4 | 175.45.176.68 | 2014-08-27 | 2025-01-29 |
Related Actors
Related Reports
Shares tag: Lazarus • Same author: Security Scorecard • Published within a month
2025-01-15 •
70% Match
#Lazarus
Shares tag: Lazarus • Same author: Security Scorecard • Published within a month
2025-02-07 •
61% Match
#ContagiousInterview
#Lazarus
#ClickFix
#T1082
#T1041
#T1555
#T1056.001
#T1027
#T1204.002
#T1555.003
#T1027.002
#T1564.001
#T1016
#T1033
#T1546.008
Shares tag: Lazarus • Shares 1 IOC • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month
Shares tag: Lazarus • Published within a month