Deep Dive: 3 Lazarus RATs Caught in Our DNS Trap
2025-09-23 • Whoisxmlapi •
https://main.whoisxmlapi.com/threat-reports/deep-dive-3-lazarus-rats-caught-in-our-dns-trap
Attachments
source_3918.pdf (994 KB)
WhoisXML API investigated DNS infrastructure tied to a Lazarus subgroup that used PondRAT, ThemeForestRAT, and RemotePE against financial and cryptocurrency organizations. The analysis covered 19 domain and two IP indicators from Fox-IT incident-response research and found traffic involving potential victims, long-lived DNS histories, and an early malicious-domain prediction for `keondigital.com`. DNS pivots produced 326 additional artifacts, including nine IPs, eight of which were already associated with malicious activity. Confirmed source indicators and explicitly malicious IP examples are separated from unverified look-alikes and connected-domain samples.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | aes-secure.net | 2025-09-01 | 2026-05-22 |
| DOMAIN | azureglobalaccelerator.com | 2025-09-01 | 2026-05-22 |
| IPv4 | 172.67.204.8 | 2025-09-23 | 2025-09-23 |
| IPv4 | 34.111.179.208 | 2025-09-23 | 2025-09-23 |
| DOMAIN | dpkgrepo.com | 2025-09-01 | 2025-09-23 |
| DOMAIN | azuredeploypackages.net | 2025-09-01 | 2025-09-23 |
| DOMAIN | pypilibrary.com | 2025-09-01 | 2025-09-23 |
| DOMAIN | lmaxtrd.com | 2025-09-01 | 2025-09-23 |
| DOMAIN | oncehub.co | 2025-09-01 | 2025-09-23 |
| DOMAIN | paxosfuture.com | 2025-09-01 | 2025-09-23 |
| DOMAIN | keondigital.com | 2025-09-01 | 2025-09-23 |
| DOMAIN | ftxstock.com | 2025-09-01 | 2025-09-23 |
| IPv4 | 192.52.166.253 | 2025-09-01 | 2025-09-23 |
| IPv4 | 144.172.74.120 | 2025-09-01 | 2025-09-23 |
| IPv4 | 23.227.38.67 | 2024-02-29 | 2025-09-23 |
| DOMAIN | arcashop.org | 2024-02-29 | 2025-09-23 |
| DOMAIN | jdkgradle.com | 2024-02-29 | 2025-09-23 |