Hidden Cobra - from a shed skin to the viper’s nest
2020-06-23 • Reversing Labs •
The recovered excerpt does not preserve the Hidden Cobra article body and instead shows a ReversingLabs blog index with multiple unrelated security headlines. The only concrete CTI item visible is a headline about 56 npm packages using binding.gyp to steal CI/CD secrets, but the excerpt provides no North Korea, Hidden Cobra, malware, infection-chain, infrastructure, or IOC detail for that item. Because the usable body lacks DPRK-linked evidence, attribution and technical defensive conclusions cannot be supported from this record alone.
Indicators of Compromise
Related Actors
Related Reports
Shares tag: HiddenCobra • Published within a month
2020-02-25 •
45% Match
#HiddenCobra
#T1082
#T1090
#T1005
#T1041
#T1083
#T1027
#T1124
#T1204
#T1057
#T1003
#T1105
#T1055
#T1016
#T1048
#T1074
#T1056
#T1033
#T1012
#T1132
#T1043
#T1060
#T1064
#T1193
#T1065
#T1050
#T1024
Shares tag: HiddenCobra
Shares tag: HiddenCobra
Shares tag: HiddenCobra
Shares tag: HiddenCobra
Shares tag: HiddenCobra