Three Lazarus RATs coming for your cheese

2025-09-01 Foxit

https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/

Thumbnail for Three Lazarus RATs coming for your cheese

Fox-IT and NCC Group analyzed a Lazarus subgroup targeting financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. In a 2024 DeFi intrusion, the actor used Telegram social engineering with fake meeting websites and likely compromised an employee machine before deploying PondRAT. The actor established persistence through SessionEnv phantom DLL loading by placing PerfhLoader in %SystemRoot%\System32\, configuring the service to start automatically, and modifying required privileges to include SeDebugPrivilege and SeLoadDriverPrivilege. After gaining a foothold, the actor used RATs and tools for discovery, screenshots, keylogging, credential harvesting, and proxying, including Mimikatz, frpc, Proxy Mini, and actor-developed utilities. PondRAT and ThemeForestRAT were used for about three months before the actor removed those artifacts and installed the more advanced RemotePE RAT, suggesting a staged intrusion lifecycle against cryptocurrency-sector targets.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 85766786fd00957737f1c88632ab9e0d 2025-09-01 2026-05-22
HASH 23c2569a65870a9e412d98d5b3bdc554 2025-09-01 2026-05-22
DOMAIN aes-secure.net 2025-09-01 2026-05-22
DOMAIN azureglobalaccelerator.com 2025-09-01 2026-05-22
HASH ff32bc1c756d560d8a9815db458f438… 2025-09-01 2026-04-03
DOMAIN calendly.com 2024-10-29 2026-03-02
HASH 85045d9898d28c9cdc4ed0ca5d76ece… 2025-09-01 2025-12-17
HASH 24d5dd3006c63d0f46fb33cbc1f5763… 2023-04-20 2025-12-17
YARA Lazarus_ThemeForestRAT_RC4_key 2025-09-01 2025-09-01
YARA Lazarus_ThemeForestRAT_C2_strin… 2025-09-01 2025-09-01
YARA Lazarus_PerfhLoader_XOR_key 2025-09-01 2025-09-01
YARA Lazarus_RemotePE_class_strings 2025-09-01 2025-09-01
YARA Lazarus_RemotePE_C2_strings 2025-09-01 2025-09-01
YARA Lazarus_DPAPILoader_Hunting 2025-09-01 2025-09-01
HASH 6510d460395ca3643133817b40d9df4… 2025-09-01 2025-09-01
HASH 59a651dfce580d28d17b2f716878a8e… 2025-09-01 2025-09-01
HASH 9dddf5a1d32e3ba7cc27f1006a843bf… 2025-09-01 2025-09-01
HASH 4f6ae0110cf652264293df571d66955… 2025-09-01 2025-09-01
HASH 1a051e4a3b62cd2d4f175fb443f5172… 2025-09-01 2025-09-01
HASH f4d8e1a687e7f7336162d3caed9b25d… 2025-09-01 2025-09-01
HASH aa4a2d1215f864481994234f13ab485… 2025-09-01 2025-09-01
HASH 8c3c8f24dc0c1d165f14e5a622a1817… 2025-09-01 2025-09-01
HASH 3c8f5cc608e3a4a755fe1a2b0991541… 2025-09-01 2025-09-01
HASH 6f2f61783a4a59449db4ba37211fa331 2025-09-01 2025-09-01
HASH e4ce73b4dbbd360a17f482abcae2d47… 2025-09-01 2025-09-01
HASH cc4c18fefb61ec5b3c69c31beaa07a4… 2025-09-01 2025-09-01
HASH 37f5afb9ed3761e73feb95daceb7a1f… 2025-09-01 2025-09-01
HASH 4715e5522fc91a423a5fcad397b571c… 2025-09-01 2025-09-01
HASH 7cc55f3cc2740e8818648efbec21615f 2025-09-01 2025-09-01
HASH 435c7b4fd5e1eaafcb5826a7e7c16a83 2025-09-01 2025-09-01
HASH c66ba5c68ba12eaf045ed415dfa72ec… 2025-09-01 2025-09-01
HASH 2c164237de4d5904a66c71843529e37… 2025-09-01 2025-09-01
HASH d998de6e40637188ccbb8ab4a27a1e7… 2025-09-01 2025-09-01
HASH 774c71664d5d25775478607e7455546… 2025-09-01 2025-09-01
HASH f0321c93c93fa162855f8ea4356628e… 2025-09-01 2025-09-01
URL https://aluigi.altervista.org/m… 2025-09-01 2025-09-01
DOMAIN dpkgrepo.com 2025-09-01 2025-09-01
DOMAIN azuredeploypackages.net 2025-09-01 2025-09-01
DOMAIN aluigi.altervista.org 2025-09-01 2025-09-01
DOMAIN pypilibrary.com 2025-09-01 2025-09-01
DOMAIN oncehub.com 2025-09-01 2025-09-01
DOMAIN go.oncehub.co 2025-09-01 2025-09-01
DOMAIN lmaxtrd.com 2025-09-01 2025-09-01
DOMAIN picktime.com 2025-09-01 2025-09-01
DOMAIN nansenpro.org 2025-09-01 2025-09-01
DOMAIN pypistorage.com 2025-09-01 2025-09-01
DOMAIN latamics.org 2025-09-01 2025-09-01
DOMAIN oncehub.co 2025-09-01 2025-09-01
DOMAIN paxosfuture.com 2025-09-01 2025-09-01
DOMAIN keondigital.com 2025-09-01 2025-09-01
DOMAIN ftxstock.com 2025-09-01 2025-09-01
IPv4 192.52.166.253 2025-09-01 2025-09-01
IPv4 144.172.74.120 2025-09-01 2025-09-01
HASH 973f7939ea03fd2c9663dafc21bb968… 2024-02-29 2025-09-01
DOMAIN arcashop.org 2024-02-29 2025-09-01
DOMAIN jdkgradle.com 2024-02-29 2025-09-01
DOMAIN slowmist.medium.com 2022-08-16 2025-09-01
HASH 5e40d106977017b1ed235419b1e59ff… 2021-02-18 2025-09-01

Related Actors

Related Reports

« Back