Three Lazarus RATs coming for your cheese
2025-09-01 • Foxit •
https://blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-for-your-cheese/
Fox-IT and NCC Group analyzed a Lazarus subgroup targeting financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. In a 2024 DeFi intrusion, the actor used Telegram social engineering with fake meeting websites and likely compromised an employee machine before deploying PondRAT. The actor established persistence through SessionEnv phantom DLL loading by placing PerfhLoader in %SystemRoot%\System32\, configuring the service to start automatically, and modifying required privileges to include SeDebugPrivilege and SeLoadDriverPrivilege. After gaining a foothold, the actor used RATs and tools for discovery, screenshots, keylogging, credential harvesting, and proxying, including Mimikatz, frpc, Proxy Mini, and actor-developed utilities. PondRAT and ThemeForestRAT were used for about three months before the actor removed those artifacts and installed the more advanced RemotePE RAT, suggesting a staged intrusion lifecycle against cryptocurrency-sector targets.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 85766786fd00957737f1c88632ab9e0d | 2025-09-01 | 2026-05-22 |
| HASH | 23c2569a65870a9e412d98d5b3bdc554 | 2025-09-01 | 2026-05-22 |
| DOMAIN | aes-secure.net | 2025-09-01 | 2026-05-22 |
| DOMAIN | azureglobalaccelerator.com | 2025-09-01 | 2026-05-22 |
| HASH | ff32bc1c756d560d8a9815db458f438… | 2025-09-01 | 2026-04-03 |
| DOMAIN | calendly.com | 2024-10-29 | 2026-03-02 |
| HASH | 85045d9898d28c9cdc4ed0ca5d76ece… | 2025-09-01 | 2025-12-17 |
| HASH | 24d5dd3006c63d0f46fb33cbc1f5763… | 2023-04-20 | 2025-12-17 |
| YARA | Lazarus_ThemeForestRAT_RC4_key | 2025-09-01 | 2025-09-01 |
| YARA | Lazarus_ThemeForestRAT_C2_strin… | 2025-09-01 | 2025-09-01 |
| YARA | Lazarus_PerfhLoader_XOR_key | 2025-09-01 | 2025-09-01 |
| YARA | Lazarus_RemotePE_class_strings | 2025-09-01 | 2025-09-01 |
| YARA | Lazarus_RemotePE_C2_strings | 2025-09-01 | 2025-09-01 |
| YARA | Lazarus_DPAPILoader_Hunting | 2025-09-01 | 2025-09-01 |
| HASH | 6510d460395ca3643133817b40d9df4… | 2025-09-01 | 2025-09-01 |
| HASH | 59a651dfce580d28d17b2f716878a8e… | 2025-09-01 | 2025-09-01 |
| HASH | 9dddf5a1d32e3ba7cc27f1006a843bf… | 2025-09-01 | 2025-09-01 |
| HASH | 4f6ae0110cf652264293df571d66955… | 2025-09-01 | 2025-09-01 |
| HASH | 1a051e4a3b62cd2d4f175fb443f5172… | 2025-09-01 | 2025-09-01 |
| HASH | f4d8e1a687e7f7336162d3caed9b25d… | 2025-09-01 | 2025-09-01 |
| HASH | aa4a2d1215f864481994234f13ab485… | 2025-09-01 | 2025-09-01 |
| HASH | 8c3c8f24dc0c1d165f14e5a622a1817… | 2025-09-01 | 2025-09-01 |
| HASH | 3c8f5cc608e3a4a755fe1a2b0991541… | 2025-09-01 | 2025-09-01 |
| HASH | 6f2f61783a4a59449db4ba37211fa331 | 2025-09-01 | 2025-09-01 |
| HASH | e4ce73b4dbbd360a17f482abcae2d47… | 2025-09-01 | 2025-09-01 |
| HASH | cc4c18fefb61ec5b3c69c31beaa07a4… | 2025-09-01 | 2025-09-01 |
| HASH | 37f5afb9ed3761e73feb95daceb7a1f… | 2025-09-01 | 2025-09-01 |
| HASH | 4715e5522fc91a423a5fcad397b571c… | 2025-09-01 | 2025-09-01 |
| HASH | 7cc55f3cc2740e8818648efbec21615f | 2025-09-01 | 2025-09-01 |
| HASH | 435c7b4fd5e1eaafcb5826a7e7c16a83 | 2025-09-01 | 2025-09-01 |
| HASH | c66ba5c68ba12eaf045ed415dfa72ec… | 2025-09-01 | 2025-09-01 |
| HASH | 2c164237de4d5904a66c71843529e37… | 2025-09-01 | 2025-09-01 |
| HASH | d998de6e40637188ccbb8ab4a27a1e7… | 2025-09-01 | 2025-09-01 |
| HASH | 774c71664d5d25775478607e7455546… | 2025-09-01 | 2025-09-01 |
| HASH | f0321c93c93fa162855f8ea4356628e… | 2025-09-01 | 2025-09-01 |
| URL | https://aluigi.altervista.org/m… | 2025-09-01 | 2025-09-01 |
| DOMAIN | dpkgrepo.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | azuredeploypackages.net | 2025-09-01 | 2025-09-01 |
| DOMAIN | aluigi.altervista.org | 2025-09-01 | 2025-09-01 |
| DOMAIN | pypilibrary.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | oncehub.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | go.oncehub.co | 2025-09-01 | 2025-09-01 |
| DOMAIN | lmaxtrd.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | picktime.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | nansenpro.org | 2025-09-01 | 2025-09-01 |
| DOMAIN | pypistorage.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | latamics.org | 2025-09-01 | 2025-09-01 |
| DOMAIN | oncehub.co | 2025-09-01 | 2025-09-01 |
| DOMAIN | paxosfuture.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | keondigital.com | 2025-09-01 | 2025-09-01 |
| DOMAIN | ftxstock.com | 2025-09-01 | 2025-09-01 |
| IPv4 | 192.52.166.253 | 2025-09-01 | 2025-09-01 |
| IPv4 | 144.172.74.120 | 2025-09-01 | 2025-09-01 |
| HASH | 973f7939ea03fd2c9663dafc21bb968… | 2024-02-29 | 2025-09-01 |
| DOMAIN | arcashop.org | 2024-02-29 | 2025-09-01 |
| DOMAIN | jdkgradle.com | 2024-02-29 | 2025-09-01 |
| DOMAIN | slowmist.medium.com | 2022-08-16 | 2025-09-01 |
| HASH | 5e40d106977017b1ed235419b1e59ff… | 2021-02-18 | 2025-09-01 |