Hunt.io and Acronis Trace Lazarus and Kimsuky Infrastructure Across Campaigns

Summary
Hunt.io and Acronis mapped DPRK-linked infrastructure, detailing a new Linux Badcall variant, credential-theft tool staging, repeated FRP deployments, and certificate-linked hosts associated with Lazarus and related activity.
Key points
- Researchers identified a Linux Badcall variant hosted on an open directory; it adds timestamped logging to track malware activity.
- Open directories contained credential-recovery tools, exfiltration utilities, Quasar RAT files, and broader offensive toolkits linked to Lazarus activity.
- Eight hosts served the same 10 MB FRP binary on port 9999, suggesting standardized or automated tunnel deployment.
- A reused certificate was linked to 12 RDP-exposed IPs; 10 were associated with Lazarus malware in the researchers’ data.
- The investigation found infrastructure overlap with Bluenoroff (APT38), while noting that shared tools alone do not establish attribution.
- The researchers recommend tracking recurring open-directory contents, FRP deployments, certificate profiles, ports, and hosting patterns.
Article Details
- Attack Vectors
- Lazarus-associated credential-recovery and browser-password utilities were found in exposed directories alongside other credential-harvesting tools.
- FRP tunneling nodes exposed identical binaries on port 9999; the article says FRP was used to proxy compromised hosts to operator-controlled servers.
- Certificate-linked hosts exposed RDP on port 3389, which the article associates with operator access and staging.
- A Linux BADCALL variant was hosted in an exposed directory and was described as daemonizing itself and logging activity to /tmp/sslvpn.log.
- Defensive Notes
- Monitor exposed directories for recurring credential-theft utilities, Quasar RAT files, Linux backdoors, rclone binaries, and repeated directory layouts.
- Hunt for identical FRP binaries and configurations exposed on port 9999, assessing them alongside hosting context and infrastructure history rather than treating FRP alone as attribution evidence.
- Pivot on reused certificate profiles and correlate hosts exposing RDP or TLS with malware and historical infrastructure telemetry.
- Track recurring combinations of hosting provider, certificate profile, exposed ports, and FRP artifacts.
Indicators of compromise
| Type | Indicator | Context |
|---|---|---|
| DOMAIN | secondshop[.]store | Lazarus-linked pivot domain leading to certificate-linked infrastructure. |
| IPV4 | 104[.]168[.]151[.]116 | Lazarus certificate-linked infrastructure with reported Bluenoroff overlap. |
| IPV4 | 104[.]168[.]198[.]145 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 118[.]123[.]54[.]71 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| IPV4 | 119[.]6[.]121[.]143 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| IPV4 | 119[.]6[.]56[.]194 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| IPV4 | 125[.]65[.]88[.]195 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| IPV4 | 125[.]67[.]171[.]158 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| IPV4 | 142[.]11[.]209[.]109 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 154[.]216[.]177[.]215 | Host exposing an operational toolkit directory, including browser password-stealers and offensive tools, associated in the article with Lazarus-linked activity. |
| IPV4 | 182[.]136[.]120[.]52 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| IPV4 | 182[.]136[.]123[.]102 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| IPV4 | 192[.]119[.]116[.]231 | Lazarus certificate-linked infrastructure with reported Bluenoroff overlap. |
| IPV4 | 192[.]236[.]146[.]20 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 192[.]236[.]146[.]22 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 192[.]236[.]176[.]164 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 192[.]236[.]233[.]162 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 192[.]236[.]233[.]165 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 192[.]236[.]236[.]100 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 23[.]254[.]128[.]114 | Lazarus certificate-linked infrastructure; the article reports historical TLS/HTTP activity and malware association. |
| IPV4 | 23[.]254[.]164[.]50 | Certificate-linked IP reported as associated with Lazarus Group malware. |
| IPV4 | 23[.]254[.]211[.]230 | Listed as a BADCALL C2 server. |
| IPV4 | 23[.]27[.]140[.]49 | Host serving the new Linux BADCALL variant from an exposed directory on port 8080. |
| IPV4 | 23[.]27[.]177[.]183 | IP identified as Lazarus-linked infrastructure and a BADCALL C2 server. |
| IPV4 | 61[.]139[.]89[.]11 | FRP infrastructure node serving the same binary on port 9999 as the other listed nodes. |
| SHA256 | 24d5dd3006c63d0f46fb33cbc1f576325d4e7e03e3201ff4a3c1ffa604f1b74a | Hash for the FRP binary observed across eight Lazarus-associated infrastructure nodes. |
| SHA256 | 36541fad68e79cdedb965b1afcdc45385646611aa72903ddbe9d4d064d7bffb9 | Hash for WebBrowserPassView found in the context of Lazarus-linked credential-theft tooling. |
| SHA256 | 85045d9898d28c9cdc4ed0ca5d76eceb457d741c5ca84bb753dde1bea980b516 | Hash listed for Poolrat. |
| SHA256 | a3876a2492f3c069c0c2b2f155b4c420d8722aa7781040b17ca27fdd4f2ce6a9 | Hash identified for the new Linux BADCALL variant. |
| SHA256 | a5350b1735190a9a275208193836432ed99c54c12c75ba6d7d4cb9838d2e2106 | Hash listed for Poolrat. |
| SHA256 | bc7bd27e94e24a301edb3d3e7fad982225ac59430fc476bda4e1459faa1c1647 | Hash for MailPassView found in the context of Lazarus-linked credential-theft tooling. |
| SHA256 | cc307cfb401d1ae616445e78b610ab72e1c7fb49b298ea003dd26ea80372089a | Hash identified for an older Linux BADCALL variant. |
| SHA256 | ff32bc1c756d560d8a9815db458f438d63b1dcb7e9930ef5b8639a55fa7762c9 | Hash listed for Poolrat. |
| URL | hxxp[:]//149[.]28[.]139[.]62:8080 | Exposed directory hosting credential-harvesting tools and Quasar RAT-related files. |
| URL | hxxp[:]//207[.]254[.]22[.]248:8800 | Exposed directory serving a credential-theft toolkit; the host was also reported as repeatedly used in malicious activity. |
MITRE ATT&CK
T1021.001 · Remote Desktop ProtocolThe article reports certificate-linked hosts exposed on RDP and describes RDP as used for operator logins and hands-on management.T1555.003 · Credentials from Web BrowsersThe article describes browser credential-extraction utilities, including WebBrowserPassView, used in Lazarus-linked credential harvesting.T1572 · Protocol TunnelingThe article describes FRP tunneling nodes used to proxy compromised hosts back to operator-controlled servers.
People
Threat Actors
APT38The article identifies APT38 as another name for Bluenoroff and reports infrastructure overlap with Lazarus-linked activity.BlueNoroffThe article reports Bluenoroff-linked activity overlapping with Lazarus certificate-linked infrastructure; it identifies Bluenoroff as APT38.KimsukyThe article attributes a campaign using a VPN-invoice-themed ZIP lure, MemLoad, and HttpTroy to Kimsuky.Lazarus GroupThe article attributes BADCALL activity, credential-theft infrastructure, FRP deployments, and certificate-linked infrastructure to Lazarus Group.
Malware
BADCALL23.27.140[.]49 open directory data on port 8080Upon analysis, the ELF exhibits similar behavior to the BADCALL backdoor that was previously seen in the 3CX supply chain attack by Lazarus. One of these,BLINDINGCANthe Lazarus Group filter. Then picked up a blog "DPRK's Playbook: Kimsuky's HttpTroy and Lazarus's New BLINDINGCAN Variant" that highlights a recent investigation linked to the Lazarus Group.HttpTroyusing IOC Hunter, applying the Lazarus Group filter. Then picked up a blog "DPRK's Playbook: Kimsuky's HttpTroy and Lazarus's New BLINDINGCAN Variant" that highlights a recent investigation linked to the LazarusMemLoadThe first campaign, attributed to Kimsuky, leveraged a VPN-invoice themed ZIP lure to drop a loader ("MemLoad") and a new backdoor dubbed "HttpTroy".Poolrata5350b1735190a9a275208193836432ed99c54c12c75ba6d7d4cb9838d2e2106 PoolratQuasar RATconsisting of 201 total files, 42 subdirectories, and over 270 MB of content. The files include a Quasar RAT infrastructure (Quasar.exe, Quasar.Common.dll, quasar.p12, profiles, clients, config files), Credential
Vendors
AcronisNote: This report is the result of a collaborative investigation between Hunt.io and the Acronis Threat Research Unit, where both teams collaborated to map ongoing DPRK infrastructure activity, including Lazarus andHunt.ioNote: This report is the result of a collaborative investigation between Hunt.io and the Acronis Threat Research Unit, where both teams collaborated to map ongoing DPRK infrastructure activity, including Lazarus and
Products
Tools
Burp SuiteThe presence of development artifacts, Burp Suite keygen links, Privoxy configs, Mimikatz folder stubs, and raw camera-roll/screenshot directories suggests the machine may represent either a compromised WindowsChromePassMB. The toolset includes password recovery utilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltrationDialupassextraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and aFast Reverse ProxyFrom IOC Hunter, we picked up another article titled "Three Lazarus RATs coming for your cheese", which highlights the use of Fast Reverse Proxy (FRP) within DPRK-linked APT campaigns.GOSTdata. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers,hack-browser-dataMSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and a data transfer tool (rclone binaries).hpingand nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browserHunt.io AttackCaptureHuntSQLthe certificate associated with the IP using the field subject.common_name == "hwc-hwp-7779700" using HuntSQL query. The result shows 12 IP Addresses all exposed with port 3389 since January 2025.IEPVPasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and a data transfer toolImpacketoffensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers, privilege-escalation binaries,IOC HunterWe started hunting DPRK APTs using IOC Hunter, applying the Lazarus Group filter. Then picked up a blog "DPRK's Playbook: Kimsuky's HttpTroy and Lazarus's New BLINDINGCAN Variant" that highlights a recent investigationMailPassViewin the report as a starting point, we extracted two SHA-256 IoCs of credential-recovery utilities, "MailPassView" and "WebBrowserPassView", both used by the Lazarus group for credential harvesting.masscanand nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates),microsocksdata. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers,MimikatzThe presence of development artifacts, Burp Suite keygen links, Privoxy configs, Mimikatz folder stubs, and raw camera-roll/screenshot directories suggests the machine may represent either a compromised WindowsMSPassutilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilitiesMythicoperating under AS30377 (MacStadium, Inc.) in Dublin, Ireland. Hunt.io's intelligence reports it as a Mythic C2 server on port 7443 in August 2025, and the IP has a recorded historical malicious open directory inNetPassrecovery utilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilitiesNgrokof operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers,Nmapand nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongsideNucleitooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browser password-stealers, privilege-escalation binaries, packet capturePasswordFoxtotaling 112 MB. The toolset includes password recovery utilities and extraction tools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large datapscptools (mailpv.exe, cli.exe, client.bin, multiple DLLs), and File-transfer and persistence utilities (pscp.exe, protobuf-net.dll, etc).PstPasswordtools (MailPassView, PasswordFox, ChromePass.exe, WebBrowserPassView, NetPass, MSPass.exe, Dialupass, PstPassword, IEPV), Large data exfiltration and profile-parsing utilities (hack-browser-data), and a data transferRCloneLarge data exfiltration and profile-parsing utilities (hack-browser-data), and a data transfer tool (rclone binaries).sqlmap1,222 subdirectories, and nearly 2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820tcpdump2 GB of operational data. The files include offensive security tooling (sqlmap, masscan, nmap, hping, tcpdump, ngrok, gost, microsocks, frpc/frps, impacket) and Nuclei (7,820 templates), alongside browserWebBrowserPassViewstarting point, we extracted two SHA-256 IoCs of credential-recovery utilities, "MailPassView" and "WebBrowserPassView", both used by the Lazarus group for credential harvesting.
Countries
Hong KongThe host "154.216.177[.]215", operating under AS135377 (LARUS Limited) in Hong Kong, exposes an exceptionally large and sensitive open directory containing 10,731 files, 1,222 subdirectories, and nearly 2 GB ofIrelandfor host 207.254.22[.]248 shows the IP Address operating under AS30377 (MacStadium, Inc.) in Dublin, Ireland. Hunt.io's intelligence reports it as a Mythic C2 server on port 7443 in August 2025, and the IP has aNorth KoreaSingapore149.28.139[.]62 shows the IP Address is hosted under AS20473 (The Constant Company, LLC / Vultr) in Singapore. Our platform identifies a distinctive Quasar RAT on port 1888 documented between September and October