Lazarus aka Hidden Cobra APT Group – Active IOCs

2024-11-15 Rewterz

https://www.rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-37279

Thumbnail for Lazarus aka Hidden Cobra APT Group – Active IOCs

Lazarus, also known as Hidden Cobra, is described as a North Korean APT active since at least 2009 with espionage and financially motivated operations against South Korea, the United States, Japan, and other countries. The advisory highlights spear phishing, malware, and social engineering, including the Dream Job campaign against cryptocurrency-adjacent targets using fake recruiter lures. It also links Lazarus to closely aligned clusters such as Bluenoroff and Andariel and provides active IOCs, including malware hashes and fake meeting or cloud sharing URLs.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0907892725021508ad379c523d17c31… 2024-11-15 2024-11-15
URL https://comma3.biz-meeting.site… 2024-11-15 2024-11-15
URL https://castleisland.sky-meetin… 2024-11-15 2024-11-15
URL https://dragonfly.cloudstore.bu… 2024-11-15 2024-11-15
DOMAIN castleisland.sky-meeting.com 2024-11-15 2024-11-15
DOMAIN comma3.biz-meeting.site 2024-11-15 2024-11-15
DOMAIN dragonfly.cloudstore.business 2024-11-15 2024-11-15
HASH e3c505b2457b1ac51c32bf428df070b… 2024-11-07 2024-11-15
HASH 75c81169d679fab821d77ea672f5a87… 2024-11-07 2024-11-15
HASH 274f4412999f561428930bd6ff38cd8… 2024-11-07 2024-11-15
HASH 54bbf9a07b0b89c0501359077aa98d7… 2024-11-07 2024-11-15

Related Actors

Related Reports

« Back