Lazarus aka Hidden Cobra APT Group – Active IOCs

2024-11-15 Rewterz

https://www.rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-37279

Thumbnail for Lazarus aka Hidden Cobra APT Group – Active IOCs

Lazarus, also known as Hidden Cobra, is described as a North Korean APT active since at least 2009 with espionage and financially motivated operations against South Korea, the United States, Japan, and other countries. The advisory highlights spear phishing, malware, and social engineering, including the Dream Job campaign against cryptocurrency-adjacent targets using fake recruiter lures. It also links Lazarus to closely aligned clusters such as Bluenoroff and Andariel and provides active IOCs, including malware hashes and fake meeting or cloud sharing URLs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 7a6b45351afef3f5d8015e0fb13342ba 2024-11-15 2024-11-15
HASH e3c505b2457b1ac51c32bf428df070b… 2024-11-15 2024-11-15
HASH 75c81169d679fab821d77ea672f5a87… 2024-11-15 2024-11-15
HASH 0907892725021508ad379c523d17c31… 2024-11-15 2024-11-15
HASH 274f4412999f561428930bd6ff38cd8… 2024-11-15 2024-11-15
HASH 54bbf9a07b0b89c0501359077aa98d7… 2024-11-15 2024-11-15
HASH 501ee5b43833e35a6be3a2f0f977bb7c 2024-11-15 2024-11-15
HASH a5396648475416fcbbedb16470ab98cc 2024-11-15 2024-11-15
HASH 98bef63ce2a1f66592169996a9764be… 2024-11-15 2024-11-15
HASH 0f5ae560bbaadc7244c6c75da30a101b 2024-11-15 2024-11-15
HASH f558987b89e65c49739f9b6f69e3c088 2024-11-15 2024-11-15
URL https://comma3.biz-meeting.site… 2024-11-15 2024-11-15
URL https://castleisland.sky-meetin… 2024-11-15 2024-11-15
URL https://dragonfly.cloudstore.bu… 2024-11-15 2024-11-15
DOMAIN castleisland.sky-meeting.com 2024-11-15 2024-11-15
DOMAIN comma3.biz-meeting.site 2024-11-15 2024-11-15
DOMAIN dragonfly.cloudstore.business 2024-11-15 2024-11-15
HASH baf4da6b89b7d7cbf24c9deef5984ef… 2024-11-07 2024-11-15
HASH 05c178891ca1e65af53bbcfdbec573d… 2024-11-07 2024-11-15
HASH e5d97afa5f1501b3d5ec1a471dc8a3b… 2024-11-07 2024-11-15
HASH 3f17c5a7d1e7fd138163d8039e614b8… 2024-11-07 2024-11-15

Related Actors

Related Reports

« Back