Hidden Cobra - from a shed skin to the viper’s nest
2020-06-23 • Reversing Labs •
ReversingLabs describes Hidden Cobra, often referred to as Lazarus, as a North Korea-linked APT and uses U.S. government reporting on COPPERHEDGE, TAINTEDSCRIBE, and PEBBLEDASH to show how defenders can expand IOC coverage. The article focuses on similarity hunting in Titanium Platform, starting from published samples and metadata such as import loading behavior, command indexes, and plaintext C2 domains. Its CTI value is finding related malware samples beyond released IOC lists, rather than reporting a new intrusion.
Indicators of Compromise
Related Actors
Related Reports
Shares tag: HiddenCobra • Published within a month
2020-02-25 •
45% Match
#HiddenCobra
#T1082
#T1090
#T1005
#T1041
#T1083
#T1027
#T1124
#T1204
#T1057
#T1003
#T1105
#T1055
#T1016
#T1048
#T1074
#T1056
#T1033
#T1012
#T1132
#T1043
#T1060
#T1064
#T1193
#T1065
#T1050
#T1024
Shares tag: HiddenCobra
Shares tag: HiddenCobra
Shares tag: HiddenCobra
Shares tag: HiddenCobra
Shares tag: HiddenCobra