APT Lazarus: Eager Crypto Beavers, Video calls and Games
ID: 2ab2efc1-9027-5d2e-b515-d3f5ba2312a8
STIX ID: report--2ab2efc1-9027-5d2e-b515-d3f5ba2312a8
Feed Name: Group-IB Blog
This report analyzes an active Lazarus APT campaign that targets job-seekers—especially blockchain and crypto professionals—by luring victims via fake interview tasks and trojanized code or cloned video-conferencing installers (FCCCall/MiroTalk). The attackers deploy BeaverTail (JS/native/Python) and InvisibleFerret with a modular CivetQ toolset to harvest browser credentials, cryptocurrency wallet data, keylogs, and application data, establish persistence (including AnyDesk unattended access), and exfiltrate data via C2 servers, FTP and Telegram; the report includes extensive IOCs (IPs, domains, file hashes, and extension IDs) and defensive recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
