Lazarus aka Hidden Cobra APT Group – Active IOCs
2024-11-15 • Rewterz •
https://www.rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-37279
Lazarus, also known as Hidden Cobra, is described as a North Korean APT active since at least 2009 with espionage and financially motivated operations against South Korea, the United States, Japan, and other countries. The advisory highlights spear phishing, malware, and social engineering, including the Dream Job campaign against cryptocurrency-adjacent targets using fake recruiter lures. It also links Lazarus to closely aligned clusters such as Bluenoroff and Andariel and provides active IOCs, including malware hashes and fake meeting or cloud sharing URLs.