Lazarus Phishing Campaign Detected (APT38)

2025-06-29 Bret Witt

https://www.youtube.com/watch?v=py4KMWYCgPk

Thumbnail for Lazarus Phishing Campaign Detected (APT38)

The excerpt describes an incident-response exercise for a high-severity alert labeled SOC337, “Lazarus Phishing Campaign Detected (APT38).” The alert involved an allowed email from [email protected] to [email protected] with the subject “Invitation: Coinbase Crypto Trader Hiring Assessment” and SMTP address 152.89.61.96. The investigation context asks whether the activity was ClickFix, phishing, a false positive, or something more malicious, and references enrichment sources including VirusTotal, Talos, OTX, urlscan, MITRE ATT&CK G0082, and Silent Push. Based on the provided body, the key value is the triage scenario and observable set rather than a confirmed intrusion outcome.

Indicators of Compromise

Type Value First Seen Last Seen
EMAIL [email protected] 2025-02-25 2025-12-16
IPv4 152.89.61.96 2025-06-29 2025-06-29

Related Actors

Related Reports

« Back