Hunt.io and Acronis Trace Lazarus and Kimsuky Infrastructure Across Campaigns

· Original article ↗

Summary

Hunt.io and Acronis mapped DPRK-linked infrastructure, detailing a new Linux Badcall variant, credential-theft tool staging, repeated FRP deployments, and certificate-linked hosts associated with Lazarus and related activity.

Key points

  • Researchers identified a Linux Badcall variant hosted on an open directory; it adds timestamped logging to track malware activity.
  • Open directories contained credential-recovery tools, exfiltration utilities, Quasar RAT files, and broader offensive toolkits linked to Lazarus activity.
  • Eight hosts served the same 10 MB FRP binary on port 9999, suggesting standardized or automated tunnel deployment.
  • A reused certificate was linked to 12 RDP-exposed IPs; 10 were associated with Lazarus malware in the researchers’ data.
  • The investigation found infrastructure overlap with Bluenoroff (APT38), while noting that shared tools alone do not establish attribution.
  • The researchers recommend tracking recurring open-directory contents, FRP deployments, certificate profiles, ports, and hosting patterns.

Article Details

Attack Vectors
  • Lazarus-associated credential-recovery and browser-password utilities were found in exposed directories alongside other credential-harvesting tools.
  • FRP tunneling nodes exposed identical binaries on port 9999; the article says FRP was used to proxy compromised hosts to operator-controlled servers.
  • Certificate-linked hosts exposed RDP on port 3389, which the article associates with operator access and staging.
  • A Linux BADCALL variant was hosted in an exposed directory and was described as daemonizing itself and logging activity to /tmp/sslvpn.log.
Defensive Notes
  • Monitor exposed directories for recurring credential-theft utilities, Quasar RAT files, Linux backdoors, rclone binaries, and repeated directory layouts.
  • Hunt for identical FRP binaries and configurations exposed on port 9999, assessing them alongside hosting context and infrastructure history rather than treating FRP alone as attribution evidence.
  • Pivot on reused certificate profiles and correlate hosts exposing RDP or TLS with malware and historical infrastructure telemetry.
  • Track recurring combinations of hosting provider, certificate profile, exposed ports, and FRP artifacts.

Indicators of compromise

TypeIndicatorContext
DOMAINsecondshop[.]storeLazarus-linked pivot domain leading to certificate-linked infrastructure.
IPV4104[.]168[.]151[.]116Lazarus certificate-linked infrastructure with reported Bluenoroff overlap.
IPV4104[.]168[.]198[.]145Certificate-linked IP reported as associated with Lazarus Group malware.
IPV4118[.]123[.]54[.]71FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
IPV4119[.]6[.]121[.]143FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
IPV4119[.]6[.]56[.]194FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
IPV4125[.]65[.]88[.]195FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
IPV4125[.]67[.]171[.]158FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
IPV4142[.]11[.]209[.]109Certificate-linked IP reported as associated with Lazarus Group malware.
IPV4154[.]216[.]177[.]215Host exposing an operational toolkit directory, including browser password-stealers and offensive tools, associated in the article with Lazarus-linked activity.
IPV4182[.]136[.]120[.]52FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
IPV4182[.]136[.]123[.]102FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
IPV4192[.]119[.]116[.]231Lazarus certificate-linked infrastructure with reported Bluenoroff overlap.
IPV4192[.]236[.]146[.]20Certificate-linked IP reported as associated with Lazarus Group malware.
IPV4192[.]236[.]146[.]22Certificate-linked IP reported as associated with Lazarus Group malware.
IPV4192[.]236[.]176[.]164Certificate-linked IP reported as associated with Lazarus Group malware.
IPV4192[.]236[.]233[.]162Certificate-linked IP reported as associated with Lazarus Group malware.
IPV4192[.]236[.]233[.]165Certificate-linked IP reported as associated with Lazarus Group malware.
IPV4192[.]236[.]236[.]100Certificate-linked IP reported as associated with Lazarus Group malware.
IPV423[.]254[.]128[.]114Lazarus certificate-linked infrastructure; the article reports historical TLS/HTTP activity and malware association.
IPV423[.]254[.]164[.]50Certificate-linked IP reported as associated with Lazarus Group malware.
IPV423[.]254[.]211[.]230Listed as a BADCALL C2 server.
IPV423[.]27[.]140[.]49Host serving the new Linux BADCALL variant from an exposed directory on port 8080.
IPV423[.]27[.]177[.]183IP identified as Lazarus-linked infrastructure and a BADCALL C2 server.
IPV461[.]139[.]89[.]11FRP infrastructure node serving the same binary on port 9999 as the other listed nodes.
SHA25624d5dd3006c63d0f46fb33cbc1f576325d4e7e03e3201ff4a3c1ffa604f1b74aHash for the FRP binary observed across eight Lazarus-associated infrastructure nodes.
SHA25636541fad68e79cdedb965b1afcdc45385646611aa72903ddbe9d4d064d7bffb9Hash for WebBrowserPassView found in the context of Lazarus-linked credential-theft tooling.
SHA25685045d9898d28c9cdc4ed0ca5d76eceb457d741c5ca84bb753dde1bea980b516Hash listed for Poolrat.
SHA256a3876a2492f3c069c0c2b2f155b4c420d8722aa7781040b17ca27fdd4f2ce6a9Hash identified for the new Linux BADCALL variant.
SHA256a5350b1735190a9a275208193836432ed99c54c12c75ba6d7d4cb9838d2e2106Hash listed for Poolrat.
SHA256bc7bd27e94e24a301edb3d3e7fad982225ac59430fc476bda4e1459faa1c1647Hash for MailPassView found in the context of Lazarus-linked credential-theft tooling.
SHA256cc307cfb401d1ae616445e78b610ab72e1c7fb49b298ea003dd26ea80372089aHash identified for an older Linux BADCALL variant.
SHA256ff32bc1c756d560d8a9815db458f438d63b1dcb7e9930ef5b8639a55fa7762c9Hash listed for Poolrat.
URLhxxp[:]//149[.]28[.]139[.]62:8080Exposed directory hosting credential-harvesting tools and Quasar RAT-related files.
URLhxxp[:]//207[.]254[.]22[.]248:8800Exposed directory serving a credential-theft toolkit; the host was also reported as repeatedly used in malicious activity.

MITRE ATT&CK

People

Threat Actors

Malware

Vendors

Products

Tools

Burp SuiteThe presence of development artifacts, Burp Suite keygen links, Privoxy configs, Mimikatz folder stubs, and raw camera-roll/screenshot directories suggests the machine may represent either a compromised WindowsChromePassMB. The toolset includes password recovery utilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltrationDialupassextraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and aFast Reverse ProxyFrom IOC Hunter, we picked up another article titled "Three Lazarus RATs coming for your cheese", which highlights the use of Fast Reverse Proxy (FRP) within DPRK-linked APT campaigns.GOSTdata. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers,hack-browser-dataMSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and a data transfer tool (rclone binaries).hpingand nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browserHunt.io AttackCaptureHuntSQLthe certificate associated with the IP using the field subject.common_name == "hwc-hwp-7779700" using HuntSQL query. The result shows 12 IP Addresses all exposed with port 3389 since January 2025.IEPVPasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and a data transfer toolImpacketoffensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers, privilege-escalation binaries,IOC HunterWe started hunting DPRK APTs using IOC Hunter, applying the Lazarus Group filter. Then picked up a blog "DPRK's Playbook: Kimsuky's HttpTroy and Lazarus's New BLINDINGCAN Variant" that highlights a recent investigationMailPassViewin the report as a starting point, we extracted two SHA-256 IoCs of credential-recovery utilities, "MailPassView" and "WebBrowserPassView", both used by the Lazarus group for credential harvesting.masscanand nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates),microsocksdata. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers,MimikatzThe presence of development artifacts, Burp Suite keygen links, Privoxy configs, Mimikatz folder stubs, and raw camera-roll/screenshot directories suggests the machine may represent either a compromised WindowsMSPassutilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilitiesMythicoperating under AS30377 (MacStadium, Inc.) in Dublin, Ireland. Hunt.io's intelligence reports it as a Mythic C2 server on port 7443 in August 2025, and the IP has a recorded historical malicious open directory inNetPassrecovery utilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilitiesNgrokof operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers,Nmapand nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongsideNucleitooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers, privilege-escalation binaries, packet capturePasswordFoxtotaling 112 MB. The toolset includes password recovery utilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large datapscptools (mailpv.exe, cli.exe, client.bin, multiple DLLs), and File-transfer and persistence utilities (pscp.exe, protobuf-net.dll, etc).PstPasswordtools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and a data transferRCloneLarge data exfiltration and profile-parsing utilities (hack-browser-data), and a data transfer tool (rclone binaries).sqlmap1,222 subdirectories, and nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820tcpdump2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browserWebBrowserPassViewstarting point, we extracted two SHA-256 IoCs of credential-recovery utilities, "MailPassView" and "WebBrowserPassView", both used by the Lazarus group for credential harvesting.

Countries

Related Articles