216.73.216.6

Pivots into New Lazarus Group Infrastructure, Acquires Sensitive Intel Related to $1.4B ByBit Hack and Past Attacks

· Published 26/02/2025 00:13 · Modified 26/02/2025 09:15

Export JSON

Essential information

Published
26/02/2025 00:13
Modified
26/02/2025 09:15
Tags
2025-02-26 apt bybit cryptocurrency north korea phishing social engineering
Related entities
1 intrusion sets (apt), 20 techniques (mitre), 2 others

Description

A significant discovery has been made regarding the Lazarus Advanced Persistent Threat () Group's infrastructure. Analysts have uncovered a domain registered by the group shortly before the $1.4 billion crypto heist, linked to an email address used in previous attacks. The investigation revealed 27 unique Astrill VPN IP addresses in logs associated with the group's test records. The ongoing campaign involves fake job interviews on LinkedIn to lure victims into downloading malware. The research also uncovered connections to multiple domains likely part of Lazarus infrastructure, with a focus on employment scams targeting the crypto community. The group's tactics include sophisticated and malware deployment methods.

External references