Rolling in the Deep(Web): Lazarus Tsunami

2025-04-25 HISolutions

https://research.hisolutions.com/2025/04/rolling-in-the-deepweb-lazarus-tsunami/

Thumbnail for Rolling in the Deep(Web): Lazarus Tsunami

HiSolutions linked a fall 2024 cryptocurrency theft against a software developer environment to the North Korea linked Contagious Interview campaign. Initial access chained a malicious BeaverTail loader from a private GitHub repository through api.npoint.io, followed by InvisibleFerret and deployment of the Tsunami framework. The Tsunami tooling used Tor and Pastebin for command and control, installed Python where needed, created startup and scheduled task persistence, added Windows Defender and firewall exclusions, and dropped components such as a Runtime Broker installer. The framework was still under development and included multiple credential stealers and cryptominers, showing continued expansion of DPRK crypto theft tooling.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN api.ipify.org 2019-12-11 2026-03-17
DOMAIN n34kr3z26f3jzp4ckmwuv5ipqyatumd… 2025-04-25 2025-11-13
URL https://api.ipify.org 2025-02-03 2025-08-28
YARA tsunami_framework 2025-04-25 2025-04-25
HASH 5473756e616d692e436f72652e436f6… 2025-04-25 2025-04-25
HASH 3769508daa5ee5955c7d0a5493b0a15… 2025-04-25 2025-04-25
HASH 11bd2c9f9e2397c9a16e0990e4ed2cf… 2025-04-25 2025-04-25
HASH 94186315edde9ab18d6772449bb0b33… 2025-04-25 2025-04-25
HASH e9571e21150d7333bfada0ef836adad… 2025-04-25 2025-04-25
HASH a2ae1da09f7508ff34bd9acc672b3cf… 2025-04-25 2025-04-25
HASH b25e1a54e9c53bf6367c449be46f322… 2025-04-25 2025-04-25
HASH 2883b1ae430003f3eff809f0461e186… 2025-04-25 2025-04-25
HASH bb3af0c03e6b0833fa268d98e5a8b19… 2025-04-25 2025-04-25
HASH f96744a85419907e7c442b13beeefb6… 2025-04-25 2025-04-25
HASH 28660b81fd4898da3b9a861af716dc2… 2025-04-25 2025-04-25
HASH 3f424b477ac16463e871726cbb106d4… 2025-04-25 2025-04-25
URL http://n34kr3z26f3jzp4ckmwuv5ip… 2025-04-25 2025-04-25
URL http://ipinfo.io/ 2025-04-25 2025-04-25
HASH ab7608bc7af2c4cdf682d3bf065dd30… 2025-03-17 2025-04-25
IPv4 23.254.229.101 2024-12-03 2025-04-25

Related Actors

Related Reports

« Back