Rolling in the Deep(Web): Lazarus Tsunami
2025-04-25 • HISolutions •
https://research.hisolutions.com/2025/04/rolling-in-the-deepweb-lazarus-tsunami/
HiSolutions linked a fall 2024 cryptocurrency theft against a software developer environment to the North Korea linked Contagious Interview campaign. Initial access chained a malicious BeaverTail loader from a private GitHub repository through api.npoint.io, followed by InvisibleFerret and deployment of the Tsunami framework. The Tsunami tooling used Tor and Pastebin for command and control, installed Python where needed, created startup and scheduled task persistence, added Windows Defender and firewall exclusions, and dropped components such as a Runtime Broker installer. The framework was still under development and included multiple credential stealers and cryptominers, showing continued expansion of DPRK crypto theft tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | api.ipify.org | 2019-12-11 | 2026-03-17 |
| DOMAIN | n34kr3z26f3jzp4ckmwuv5ipqyatumd… | 2025-04-25 | 2025-11-13 |
| URL | https://api.ipify.org | 2025-02-03 | 2025-08-28 |
| YARA | tsunami_framework | 2025-04-25 | 2025-04-25 |
| HASH | 5473756e616d692e436f72652e436f6… | 2025-04-25 | 2025-04-25 |
| HASH | 3769508daa5ee5955c7d0a5493b0a15… | 2025-04-25 | 2025-04-25 |
| HASH | 11bd2c9f9e2397c9a16e0990e4ed2cf… | 2025-04-25 | 2025-04-25 |
| HASH | 94186315edde9ab18d6772449bb0b33… | 2025-04-25 | 2025-04-25 |
| HASH | e9571e21150d7333bfada0ef836adad… | 2025-04-25 | 2025-04-25 |
| HASH | a2ae1da09f7508ff34bd9acc672b3cf… | 2025-04-25 | 2025-04-25 |
| HASH | b25e1a54e9c53bf6367c449be46f322… | 2025-04-25 | 2025-04-25 |
| HASH | 2883b1ae430003f3eff809f0461e186… | 2025-04-25 | 2025-04-25 |
| HASH | bb3af0c03e6b0833fa268d98e5a8b19… | 2025-04-25 | 2025-04-25 |
| HASH | f96744a85419907e7c442b13beeefb6… | 2025-04-25 | 2025-04-25 |
| HASH | 28660b81fd4898da3b9a861af716dc2… | 2025-04-25 | 2025-04-25 |
| HASH | 3f424b477ac16463e871726cbb106d4… | 2025-04-25 | 2025-04-25 |
| URL | http://n34kr3z26f3jzp4ckmwuv5ip… | 2025-04-25 | 2025-04-25 |
| URL | http://ipinfo.io/ | 2025-04-25 | 2025-04-25 |
| HASH | ab7608bc7af2c4cdf682d3bf065dd30… | 2025-03-17 | 2025-04-25 |
| IPv4 | 23.254.229.101 | 2024-12-03 | 2025-04-25 |