Lazarus aka Hidden Cobra APT Group – Active IOCs
2024-12-20 • Rewterz •
https://www.rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-37728
Lazarus is described as a North Korea-linked threat actor active since at least 2009, with activity spanning South Korea, the United States, Japan, and other countries. The excerpt says the group has targeted financial institutions, government agencies, military organizations, and cryptocurrency-adjacent entities, with operations involving espionage, financially motivated attacks, cryptocurrency theft, and ransomware-linked activity. The cited Dream Job campaign uses recruiter impersonation and social engineering to convince targets to download malware. The advisory provides hash indicators of compromise and recommends controls such as patching, multi-factor authentication, cautious handling of email attachments, backups, and blocking or hunting the listed indicators.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | arcashop.org | 2024-02-29 | 2025-09-01 |
| HASH | d042afa59dd81cc9e0d0e50e3cc8694… | 2024-12-20 | 2024-12-20 |
| HASH | 34bd23adddc3ca5e252d89fed27225bd | 2024-12-20 | 2024-12-20 |
| HASH | 56a666601e66a01cc8dcb53a470d9ea… | 2024-12-20 | 2024-12-20 |
| HASH | b1f371ef6f978b44258ab235e79de39… | 2024-12-20 | 2024-12-20 |
| HASH | c4ce18cb838eb61d20a857e00589b0a… | 2024-12-20 | 2024-12-20 |
| HASH | 785028ccb1763c504626d3678a0c8fe7 | 2024-12-20 | 2024-12-20 |
| HASH | b8daba7780619f9a9001cf391c74a5e… | 2024-12-20 | 2024-12-20 |
| HASH | 317d733031850427b6738dc9213890e… | 2024-12-20 | 2024-12-20 |
| HASH | 92b770b39e51c618a8556e2a5f8989a8 | 2024-12-20 | 2024-12-20 |
| DOMAIN | atokyonews.com | 2024-12-06 | 2024-12-20 |