{
    "type": "bundle",
    "id": "bundle--0455f544-30d0-4a4a-9d83-ee7e493ff107",
    "objects": [
        {
            "type": "identity",
            "spec_version": "2.1",
            "id": "identity--18a3a1f0-eb3d-4bbc-904e-ee52948913a7",
            "created": "2023-03-08T12:51:43.431426Z",
            "modified": "2023-03-08T12:51:43.431505Z",
            "name": "Malwarebytes",
            "identity_class": "organization"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--94648ddc-b36f-4fba-b677-f505b837738b",
            "value": "rebelthumb.net"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--92cc17ac-90c9-4cc1-8981-73d62ad5bc4e",
            "value": "strainservice.com"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--ce341c5b-0017-42ce-b95f-0826b6c4be6d",
            "value": "wirexpro.com"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--7a6ebb44-51c2-43d5-bcc3-2f8e9f9f0b43",
            "value": "oilycargo.com"
        },
        {
            "type": "file",
            "spec_version": "2.1",
            "id": "file--42a2b0ef-6734-4e6c-a1d0-8fb3335bf762",
            "hashes": {
                "MD5": "18e190413af045db88dfbd29609eb877"
            }
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--5f5bff32-03f0-4fd0-ac37-9a49ab8d1da6",
            "value": "telloo.io"
        },
        {
            "type": "domain-name",
            "spec_version": "2.1",
            "id": "domain-name--f7da1fa0-deaf-47dd-86e7-cab99879c3fa",
            "value": "bloxholder.com"
        },
        {
            "type": "threat-actor",
            "spec_version": "2.1",
            "id": "threat-actor--a6b38f84-4a9c-5481-ad0c-9b5ee8bd5a96",
            "created": "2026-06-24T22:42:12.578984Z",
            "modified": "2026-06-24T22:42:12.578984Z",
            "name": "APT38"
        },
        {
            "type": "report",
            "spec_version": "2.1",
            "id": "report--72a07f17-7e95-4ec2-9399-5955462d35d6",
            "created_by_ref": "identity--18a3a1f0-eb3d-4bbc-904e-ee52948913a7",
            "created": "2026-06-24T22:42:12.582998Z",
            "modified": "2026-06-24T22:42:12.582998Z",
            "name": "Lazarus group uses fake cryptocurrency apps to plant AppleJeus malware",
            "published": "2022-12-05T00:00:00Z",
            "object_refs": [
                "identity--18a3a1f0-eb3d-4bbc-904e-ee52948913a7",
                "domain-name--94648ddc-b36f-4fba-b677-f505b837738b",
                "domain-name--92cc17ac-90c9-4cc1-8981-73d62ad5bc4e",
                "domain-name--ce341c5b-0017-42ce-b95f-0826b6c4be6d",
                "domain-name--7a6ebb44-51c2-43d5-bcc3-2f8e9f9f0b43",
                "file--42a2b0ef-6734-4e6c-a1d0-8fb3335bf762",
                "domain-name--5f5bff32-03f0-4fd0-ac37-9a49ab8d1da6",
                "domain-name--f7da1fa0-deaf-47dd-86e7-cab99879c3fa",
                "threat-actor--a6b38f84-4a9c-5481-ad0c-9b5ee8bd5a96"
            ],
            "external_references": [
                {
                    "source_name": "source",
                    "url": "https://www.malwarebytes.com/blog/news/2022/12/lazarus-group-uses-fake-cryptocurrency-apps-to-plant-applejeus-malware"
                }
            ]
        }
    ]
}