Lazarus aka Hidden Cobra APT Group – Active IOCs

2024-12-20 Rewterz

https://www.rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-37728

Thumbnail for Lazarus aka Hidden Cobra APT Group – Active IOCs

Lazarus is described as a North Korea-linked threat actor active since at least 2009, with activity spanning South Korea, the United States, Japan, and other countries. The excerpt says the group has targeted financial institutions, government agencies, military organizations, and cryptocurrency-adjacent entities, with operations involving espionage, financially motivated attacks, cryptocurrency theft, and ransomware-linked activity. The cited Dream Job campaign uses recruiter impersonation and social engineering to convince targets to download malware. The advisory provides hash indicators of compromise and recommends controls such as patching, multi-factor authentication, cautious handling of email attachments, backups, and blocking or hunting the listed indicators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN arcashop.org 2024-02-29 2025-09-01
HASH d042afa59dd81cc9e0d0e50e3cc8694… 2024-12-20 2024-12-20
HASH 34bd23adddc3ca5e252d89fed27225bd 2024-12-20 2024-12-20
HASH 56a666601e66a01cc8dcb53a470d9ea… 2024-12-20 2024-12-20
HASH b1f371ef6f978b44258ab235e79de39… 2024-12-20 2024-12-20
HASH c4ce18cb838eb61d20a857e00589b0a… 2024-12-20 2024-12-20
HASH 785028ccb1763c504626d3678a0c8fe7 2024-12-20 2024-12-20
HASH b8daba7780619f9a9001cf391c74a5e… 2024-12-20 2024-12-20
HASH 317d733031850427b6738dc9213890e… 2024-12-20 2024-12-20
HASH 92b770b39e51c618a8556e2a5f8989a8 2024-12-20 2024-12-20
DOMAIN atokyonews.com 2024-12-06 2024-12-20

Related Actors

Related Reports

« Back