Follow the Clues: Everyday is lazarus.day

2025-01-21 lazarusholic

https://jsac.jpcert.or.jp/archive/2025/pdf/JSAC2025_1_6_jeonggak-lyu_en.pdf

Attachments

JSAC2025_1_6_jeonggak-lyu_en.pdf (4 MB)

Thumbnail for Follow the Clues: Everyday is lazarus.day

The JSAC source presents Lazarus-focused CTI methods for following clues across malware, infrastructure, and external knowledge bases such as Malpedia and the Pyramid of Pain. The report is useful as analytic tradecraft for strengthening Lazarus attribution and detection by correlating indicators with higher-level behaviors rather than relying only on low-confidence IOCs. It supports defenders investigating DPRK-linked campaigns and mapping evidence across reports, tools, and observed intrusion artifacts.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN cryptocopedia.com 2024-07-08 2025-05-16

Related Reports

« Back