Deep Dive: 3 Lazarus RATs Caught in Our DNS Trap

2025-09-23 Whoisxmlapi

https://main.whoisxmlapi.com/threat-reports/deep-dive-3-lazarus-rats-caught-in-our-dns-trap

Attachments

source_3918.pdf (994 KB)

Thumbnail for Deep Dive: 3 Lazarus RATs Caught in Our DNS Trap

WhoisXML API investigated DNS infrastructure tied to a Lazarus subgroup that used PondRAT, ThemeForestRAT, and RemotePE against financial and cryptocurrency organizations. The analysis covered 19 domain and two IP indicators from Fox-IT incident-response research and found traffic involving potential victims, long-lived DNS histories, and an early malicious-domain prediction for `keondigital.com`. DNS pivots produced 326 additional artifacts, including nine IPs, eight of which were already associated with malicious activity. Confirmed source indicators and explicitly malicious IP examples are separated from unverified look-alikes and connected-domain samples.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN aes-secure.net 2025-09-01 2026-05-22
DOMAIN azureglobalaccelerator.com 2025-09-01 2026-05-22
IPv4 172.67.204.8 2025-09-23 2025-09-23
IPv4 34.111.179.208 2025-09-23 2025-09-23
DOMAIN dpkgrepo.com 2025-09-01 2025-09-23
DOMAIN azuredeploypackages.net 2025-09-01 2025-09-23
DOMAIN pypilibrary.com 2025-09-01 2025-09-23
DOMAIN lmaxtrd.com 2025-09-01 2025-09-23
DOMAIN oncehub.co 2025-09-01 2025-09-23
DOMAIN paxosfuture.com 2025-09-01 2025-09-23
DOMAIN keondigital.com 2025-09-01 2025-09-23
DOMAIN ftxstock.com 2025-09-01 2025-09-23
IPv4 192.52.166.253 2025-09-01 2025-09-23
IPv4 144.172.74.120 2025-09-01 2025-09-23
IPv4 23.227.38.67 2024-02-29 2025-09-23
DOMAIN arcashop.org 2024-02-29 2025-09-23
DOMAIN jdkgradle.com 2024-02-29 2025-09-23

Related Actors

Related Reports

« Back