Operation Phantom Circuit: North Korea's Global Data Exfiltration Campaign
Jan. 30, 2025, 4:33 p.m.
Description
In December 2024, the Lazarus Group, a North Korean threat actor, launched a sophisticated global campaign targeting cryptocurrency and technology developers. The operation, code-named 'Phantom Circuit,' involved embedding malware into trusted development tools, compromising hundreds of victims worldwide. The attackers utilized advanced obfuscation techniques, including proxy servers in Russia, to evade detection. The campaign unfolded in three waves, affecting over 1,500 systems globally. The infrastructure included command-and-control servers, spoofed domains, and persistent remote management sessions. The attackers exfiltrated critical data, including development credentials and authentication tokens, storing it in Dropbox. The operation's administrative platform showcased advanced capabilities in managing stolen data, emphasizing the group's technical expertise and planning.
Tags
Date
- Created: Jan. 30, 2025, 4:13 p.m.
- Published: Jan. 30, 2025, 4:13 p.m.
- Modified: Jan. 30, 2025, 4:33 p.m.
Indicators
- 94.131.9.32
- 86.104.74.51
- 5.253.43.122
- 45.128.52.14
- 185.153.182.241
- 175.45.178.9
- 175.45.178.14
- 175.45.178.10
- 175.45.178.11
- 175.45.178.130
- 175.45.176.68
- 175.45.176.27
- sageskills-uk.com
Additional Informations
- Technology
- Finance
- India
- Russian Federation