lazarusholic

Everyday is lazarus.dayβ

Lazarus aka Hidden Cobra APT Group – Active IOCs

2024-11-21, Rewterz
https://www.rewterz.com/threat-advisory/lazarus-aka-hidden-cobra-apt-group-active-iocs-37353
#Lazarus

Contents

Analysis Summary
Lazarus APT is one of North Korea's most sophisticated threat actors, and it has been operating since at least 2009. Initially, they concentrated on South Korea. It has recently shifted its focus to worldwide targets and began initiating attacks for monetary gain. This actor has been linked to attacks in South Korea, the United States, Japan, and several other nations. Lazarus APT is suspected of being behind several diverse efforts, including cyber espionage, and attacks on financial institutions, government agencies, and the military.
The Lazarus group has been known to use a variety of tactics, techniques, and procedures TTPs in their operations, including spear-phishing, malware, and social engineering. One of their recent campaigns, "Dream Job," specifically targets cryptocurrency-adjacent entities by impersonating legitimate job recruiters and tricking individuals into downloading malware.
The Lazarus Group is a highly sophisticated and well-funded organization and is considered one of the most significant threats to organizations …

IoC

782aadc761381ec79e8d01a5ed4d13ae6089661ff2517c88e6de6d6eb2c89cab
4ca9cad959d64599e85ecb45232cb8a6
ac146406fa4781454cab035d4fe3f244
c8549d0773855ce9a0b74d814da3e119
5f549663a4836ee2ea82c79aa786f2541cd8f421
ab1071c25ce763072f6b85302a83024833e724ffc51075da5bf915860a674874
17f9e40a0315699e7b7e69397b661d5af66dd871
37ff1f0febf3131bd82dcfd30bb83f96b04aed7b
e7923f6672cfc24f47982c3c5b8aa967bf83de3b05bb3f199c4cb6c4aa89b84d
bf6b4a30f1e5b4f4156446adc7693236
4d056026488c0c9a2e15d915fde87dbe202b3126
7c059314638fd78ce3d0f375bae16a615860d603d1b157edeb4eabf797347d35