Alliances of convenience: How APTs are beginning to work together

2025-11-19 Gen Digital

https://www.gendigital.com/blog/insights/research/apt-cyber-alliances-2025

Thumbnail for Alliances of convenience: How APTs are beginning to work together

Gen researchers identified a possible operational overlap between Russia-aligned Gamaredon and North Korea's Lazarus through shared use of IP address 144.172.112.106. The server was first blocked as part of Gamaredon command-and-control tracking and, four days later, was found hosting an obfuscated InvisibleFerret payload consistent with Lazarus Contagious Interview infrastructure. The payload was served from a matching /payload/99/81 path, but the report assesses the overlap with moderate confidence because a proxy, VPN endpoint, or shared client instance cannot be ruled out. A separate case involving 216.219.87.41 reappearing across Lazarus and Kimsuky-linked payloads reinforces the defender need to correlate infrastructure across DPRK-linked and allied state activity rather than relying on single-actor attribution.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 144.172.112.106 2025-08-12 2026-01-21
DOMAIN stake.com 2023-09-05 2025-12-31
HASH f4d10604980f8f556440460adc71883… 2025-11-19 2025-11-19
HASH 128da948f7c3a6c052e782acfee5033… 2025-11-19 2025-11-19
HASH cce27340fd6f32d96c65b7b1034c65d… 2025-11-19 2025-11-19
HASH 8bb089d763d5d4b4f96ae59eb9d8f91… 2025-11-19 2025-11-19
IPv4 216.219.87.41 2025-11-19 2025-11-19

Related Actors

Related Reports

« Back