logo

Operation-Marstech-Mayhem-Report_021025_03.pdf

ID: 0c2288eb-3005-4549-821d-1dab6d8af58f

STIX ID: report--0c2288eb-3005-4549-821d-1dab6d8af58f

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2025-02-10

Last Modified Date: 2025-02-10

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
STRIKE attributes "Operation Marstech Mayhem" to the Lazarus Group: a multi-stage supply-chain campaign using an obfuscated JavaScript implant (Marstech1) and Python components to target developers and cryptocurrency wallets (e.g., MetaMask, Exodus, Atomic). The report documents active C2 infrastructure (notable IPs and ports), GitHub-based distribution from a profile named 'SuccessFriend', advanced obfuscation (control-flow flattening, Base85+XOR), browser-extension tampering to inject malicious payloads, and data exfiltration to /uploads endpoints, emphasizing high operational sophistication and risk to developer supply chains and crypto users.