Alliances of convenience: How APTs are beginning to work together
2025-11-19 • Gen Digital •
https://www.gendigital.com/blog/insights/research/apt-cyber-alliances-2025
Gen researchers identified a possible operational overlap between Russia-aligned Gamaredon and North Korea's Lazarus through shared use of IP address 144.172.112.106. The server was first blocked as part of Gamaredon command-and-control tracking and, four days later, was found hosting an obfuscated InvisibleFerret payload consistent with Lazarus Contagious Interview infrastructure. The payload was served from a matching /payload/99/81 path, but the report assesses the overlap with moderate confidence because a proxy, VPN endpoint, or shared client instance cannot be ruled out. A separate case involving 216.219.87.41 reappearing across Lazarus and Kimsuky-linked payloads reinforces the defender need to correlate infrastructure across DPRK-linked and allied state activity rather than relying on single-actor attribution.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 144.172.112.106 | 2025-08-12 | 2026-01-21 |
| DOMAIN | stake.com | 2023-09-05 | 2025-12-31 |
| HASH | f4d10604980f8f556440460adc71883… | 2025-11-19 | 2025-11-19 |
| HASH | 128da948f7c3a6c052e782acfee5033… | 2025-11-19 | 2025-11-19 |
| HASH | cce27340fd6f32d96c65b7b1034c65d… | 2025-11-19 | 2025-11-19 |
| HASH | 8bb089d763d5d4b4f96ae59eb9d8f91… | 2025-11-19 | 2025-11-19 |
| IPv4 | 216.219.87.41 | 2025-11-19 | 2025-11-19 |