216.73.217.22

APT-C-26 (Lazarus) continues to upgrade its attack weapons, using Electron programs to target the cryptocurrency industry

· Published 22/01/2025 09:10 · Modified 22/01/2025 09:46

Export JSON

Essential information

Published
22/01/2025 09:10
Modified
22/01/2025 09:46
Tags
2025-01-22 cryptocurrency data theft electron uniswapsniperbot
Related entities
1 intrusion sets (apt), 13 techniques (mitre), 2 others

Description

The APT-C-26 (Lazarus) group has been observed using -packaged malicious programs disguised as trading tools to target individuals in the industry. The attack involves a multi-stage process, including the use of poisoned open-source projects, obfuscated malicious code, and various downloaders to steal sensitive information and wallet data. The group demonstrates sophisticated techniques, including strong code obfuscation and multi-platform attack capabilities. The malware performs functions such as host monitoring, file theft, and browser data exfiltration. The analysis reveals similarities with previous Lazarus campaigns, including the use of Python and JavaScript-based tools, as well as consistent C&C server patterns.

External references