ESET Threat Report T2 2022
2022-10-05 • ESET •
https://www.welivesecurity.com/wp-content/uploads/2022/10/eset_threat_report_t22022.pdf
Attachments
ESET’s T2 2022 threat report flags Lazarus activity within a broader threat landscape review, including an Operation In(ter)ception campaign against macOS users. The DPRK-linked section says the malware was disguised as a Coinbase cryptocurrency-platform job description, consistent with Lazarus social-engineering themes around cryptocurrency and recruitment. The report also notes ESET research into Lazarus payloads in trojanized applications and conference disclosures on Lazarus campaigns, making the item relevant for tracking DPRK-linked malware delivery and crypto-sector targeting.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | outlook.com | 2018-09-06 | 2026-04-17 |
| DOMAIN | blogs.blackberry.com | 2021-02-28 | 2024-04-11 |
| HASH | c0af4b8268b4ec4c292409326bfcf5e… | 2022-10-05 | 2022-10-05 |
| HASH | 1b088545db98018b1b6c3909d4e879c… | 2022-10-05 | 2022-10-05 |
| HASH | 6bccee7b6817c8af6a737c24c25e884… | 2022-10-05 | 2022-10-05 |
| HASH | da115c7f06d6e27f4d388104dc64d82… | 2022-10-05 | 2022-10-05 |
| URL | https://www.thedrive.com/news/h… | 2022-10-05 | 2022-10-05 |
| URL | https://www.coveware.com/blog/2… | 2022-10-05 | 2022-10-05 |
| URL | https://www.cleafy.com/cleafy-l… | 2022-10-05 | 2022-10-05 |
| URL | https://www.thedrive.com/tech/i… | 2022-10-05 | 2022-10-05 |
| DOMAIN | arafifblues.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | bsidesmtl.ca | 2022-10-05 | 2022-10-05 |
| DOMAIN | attackevals.mitre-engenuity.org | 2022-10-05 | 2022-10-05 |
| DOMAIN | google-qa.net | 2022-10-05 | 2022-10-05 |
| DOMAIN | serch07.biz | 2022-10-05 | 2022-10-05 |
| DOMAIN | v.vfghe.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | vk-online.xyz | 2022-10-05 | 2022-10-05 |
| DOMAIN | mybetterck.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | cfp.recon.cx | 2022-10-05 | 2022-10-05 |
| DOMAIN | mrproddisup.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | gsgazete.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | survey-smiles.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | tech4-you.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | hilarion-lar.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | sector.ca | 2022-10-05 | 2022-10-05 |
| DOMAIN | iclickcdn.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | mituus.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | broworker1s.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | buikolered.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | jecromaha.info | 2022-10-05 | 2022-10-05 |
| DOMAIN | kaizoku-ehime.jp | 2022-10-05 | 2022-10-05 |
| DOMAIN | ar.insuit.net | 2022-10-05 | 2022-10-05 |
| DOMAIN | bwukxn.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | thecred.info | 2022-10-05 | 2022-10-05 |
| DOMAIN | wypracowanie.edu | 2022-10-05 | 2022-10-05 |
| DOMAIN | foreign-movies.baby-supernode.x… | 2022-10-05 | 2022-10-05 |
| DOMAIN | dl-x.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | geotimes.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | webanalyser.org | 2022-10-05 | 2022-10-05 |
| DOMAIN | webminepool.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | cellar.z5h64q92x9.net | 2022-10-05 | 2022-10-05 |
| DOMAIN | d1ywb8dvwodsnl.cloudfront.net | 2022-10-05 | 2022-10-05 |
| DOMAIN | tabledownstairsprovocative.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | watchvideoplayer.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | mainevnap.com | 2022-10-05 | 2022-10-05 |
| DOMAIN | loft.z5h64q92x9.net | 2022-10-05 | 2022-10-05 |
| DOMAIN | codeblue.jp | 2022-10-05 | 2022-10-05 |