Operation Phantom Circuit: North Korea's Global Data Exfiltration Campaign

2025-01-29 Security Scorecard

https://securityscorecard.com/blog/operation-phantom-circuit-north-koreas-global-data-exfiltration-campaign/

Attachments

Operation-Phantom-Circuit-Report_012725_03.pdf (1 MB)

Thumbnail for Operation Phantom Circuit: North Korea's Global Data Exfiltration Campaign

SecurityScorecard describes Operation Phantom Circuit as a Lazarus Group campaign that embedded malware in trusted development tools to compromise cryptocurrency and technology developers worldwide. The infrastructure used C2 servers active from late 2024 into January 2025, a hidden administrative platform, spoofed domains, VPN and proxy routing through Hasan, Russia, and Dropbox for exfiltrated data storage. STRIKE reported more than 1,500 compromised systems across three waves, with stolen development credentials, authentication tokens, browser passwords, and system information collected from victims.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.128.52.14 2025-01-29 2025-11-13
IPv4 185.153.182.241 2025-01-29 2025-11-13
IPv4 5.253.43.122 2025-01-29 2025-11-13
IPv4 86.104.74.51 2024-12-03 2025-11-13
IPv4 94.131.9.32 2025-01-29 2025-05-13
DOMAIN sageskills-uk.com 2025-01-29 2025-01-29
DOMAIN skillsage.uk 2025-01-29 2025-01-29
IPv4 204.188.233.68 2025-01-29 2025-01-29
IPv4 70.39.70.196 2025-01-29 2025-01-29
IPv4 175.45.178.130 2025-01-29 2025-01-29
IPv4 83.234.227.53 2025-01-29 2025-01-29
IPv4 175.45.178.9 2025-01-29 2025-01-29
IPv4 83.234.227.52 2025-01-29 2025-01-29
IPv4 175.45.178.11 2025-01-29 2025-01-29
IPv4 83.234.227.49 2025-01-29 2025-01-29
IPv4 70.39.70.197 2025-01-29 2025-01-29
IPv4 83.234.227.51 2025-01-29 2025-01-29
IPv4 83.234.227.50 2025-01-29 2025-01-29
IPv4 45.58.143.196 2025-01-29 2025-01-29
IPv4 199.115.99.62 2025-01-29 2025-01-29
IPv4 175.45.178.10 2025-01-29 2025-01-29
IPv4 175.45.178.14 2025-01-29 2025-01-29
IPv4 175.45.176.27 2023-02-02 2025-01-29
IPv4 175.45.176.68 2014-08-27 2025-01-29

Related Actors

Related Reports

« Back