Lazarus aka Hidden Cobra APT Group – Active IOCs

2024-12-20 Rewterz

https://www.rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-37728

Thumbnail for Lazarus aka Hidden Cobra APT Group – Active IOCs

Lazarus is described as a North Korea-linked threat actor active since at least 2009, with activity spanning South Korea, the United States, Japan, and other countries. The excerpt says the group has targeted financial institutions, government agencies, military organizations, and cryptocurrency-adjacent entities, with operations involving espionage, financially motivated attacks, cryptocurrency theft, and ransomware-linked activity. The cited Dream Job campaign uses recruiter impersonation and social engineering to convince targets to download malware. The advisory provides hash indicators of compromise and recommends controls such as patching, multi-factor authentication, cautious handling of email attachments, backups, and blocking or hunting the listed indicators.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN arcashop.org 2024-02-29 2025-09-23
HASH b1f371ef6f978b44258ab235e79de39… 2024-12-20 2024-12-20
HASH 56a666601e66a01cc8dcb53a470d9ea… 2024-12-20 2024-12-20
HASH 317d733031850427b6738dc9213890e… 2024-12-20 2024-12-20
DOMAIN atokyonews.com 2024-12-06 2024-12-20

Related Actors

Related Reports

« Back