PULSE NAME
Inside DPRK Operations: New Infrastructure Uncovered Across Global Campaigns
WHITE Lazarus Group, Kimsuky AlienVault 2025-12-18 Modified: 2026-01-17
26
IOCs
MEDIUM VOLUME
North Korean state-sponsored threat actors, including Lazarus and Kimsuky, continue to conduct widespread hacking operations for intelligence gathering, financial gain, and access. The investigation uncovered previously unconnected operational assets, revealing active tool-staging servers, credential theft environments, FRP tunneling nodes, and certificate-linked infrastructure. Key findings include a new Linux variant of the Badcall backdoor, extensive credential harvesting toolkits in open directories, and widespread deployment of Fast Reverse Proxy (FRP) instances. The analysis highlights consistent operational patterns across DPRK campaigns, such as reusing infrastructure, deploying identical FRP configurations, and leveraging shared certificates, providing defenders with actionable intelligence to proactively track DPRK activity.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
BADCALL - S0245 HttpTroy BLINDINGCAN - S0520 Quasar RAT MailPassView WebBrowserPassView
Indicators of Compromise (26)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2025-55182 2025-12-18
FileHash-MD5 0ceb38f7c3d464a8268f67559755b216 2025-12-18
FileHash-MD5 0fcd0296caead9343fcdad3584f64a18 2025-12-18
FileHash-MD5 19dbffec4e359a198daf4ffca1ab9165 2025-12-18
FileHash-MD5 298ef0317beb4d6c3e1f1dbe1ee6f244 2025-12-18
FileHash-MD5 2cf6a67e6043747d90e1bc0ce69a974a 2025-12-18
FileHash-MD5 aac5a52b939f3fe792726a13ff7a1747 2025-12-18
FileHash-MD5 ad90013ab20c2bc2da850a45a9f5d3c8 2025-12-18
FileHash-MD5 cab3948912818c6a44a52ed44017b43a 2025-12-18
FileHash-SHA1 22932aac0e65e2013428d5cae7cd76fb4682b012 2025-12-18
FileHash-SHA1 5aac78b6ee9784d9d021b2e326adcdd770d1bd2a 2025-12-18
FileHash-SHA1 793e43699602c78105abd265fbbb00a4cfe03755 2025-12-18
FileHash-SHA1 a45ca236442a7ed36ac9dec298fb2eef7766652b 2025-12-18
FileHash-SHA1 abeb2abdf0eb7bcab61605bae95618f394ba8835 2025-12-18
FileHash-SHA1 c5b998332f57ba49ded8d79c255aa18d38c8e7dd 2025-12-18
FileHash-SHA1 d7ba13662fbfb254acaad7ae10ad51e0bd631933 2025-12-18
FileHash-SHA1 f6760fb1f8b019af2304ea6410001b63a1809f1d 2025-12-18
FileHash-SHA256 24d5dd3006c63d0f46fb33cbc1f576325d4e7e03e3201ff4a3c1ffa604f1b74a 2025-12-18
FileHash-SHA256 36541fad68e79cdedb965b1afcdc45385646611aa72903ddbe9d4d064d7bffb9 2025-12-18
FileHash-SHA256 85045d9898d28c9cdc4ed0ca5d76eceb457d741c5ca84bb753dde1bea980b516 2025-12-18
FileHash-SHA256 a3876a2492f3c069c0c2b2f155b4c420d8722aa7781040b17ca27fdd4f2ce6a9 2025-12-18
FileHash-SHA256 a5350b1735190a9a275208193836432ed99c54c12c75ba6d7d4cb9838d2e2106 2025-12-18
FileHash-SHA256 bc7bd27e94e24a301edb3d3e7fad982225ac59430fc476bda4e1459faa1c1647 2025-12-18
FileHash-SHA256 cc307cfb401d1ae616445e78b610ab72e1c7fb49b298ea003dd26ea80372089a 2025-12-18
FileHash-SHA256 ff32bc1c756d560d8a9815db458f438d63b1dcb7e9930ef5b8639a55fa7762c9 2025-12-18
domain secondshop.store 2025-12-18