Overview 5,380 indicators
Lazarus Group is a North Korean state-sponsored cyber threat group attributed to the Reconnaissance General Bureau (RGB). Lazarus Group has been active since at least 2009 and is reportedly responsible for the November 2014 destructive wiper attack on Sony Pictures Entertainment, identified by Novetta as part of Operation Blockbuster. Malware used by Lazarus Group correlates to other reported campaigns, including Operation Flame, Operation 1Mission, Operation Troy, DarkSeoul, and Ten Days of Rain. North Korea’s cyber operations have shown a consistent pattern of adaptation, forming and reorganizing units as national priorities shift. These units frequently share personnel, infrastructure, malware, and tradecraft, making it difficult to attribute specific operations with high confidence. Public reporting often uses “Lazarus Group” as an umbrella term for multiple North Korean cyber operators conducting espionage, destructive attacks, and financially motivated campaigns.
| domain | 3,836 | G0032-domain.txt |
| ipv4 | 830 | G0032.json |
| url | 624 | G0032.json |
| url_path | 90 | G0032.json |
Techniques 93 ATT&CK
Open in ATT&CK Navigator → or download the layer (93 techniques, layer 4.5)
- T1001.003 Protocol or Service Impersonation
- T1005 Data from Local System
- T1008 Fallback Channels
- T1010 Application Window Discovery
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1021.001 Remote Desktop Protocol
- T1021.002 SMB/Windows Admin Shares
- T1021.004 SSH
- T1027.007 Dynamic API Resolution
- T1027.009 Embedded Payloads
- T1027.013 Encrypted/Encoded File
- T1033 System Owner/User Discovery
- T1036.003 Rename Legitimate Utilities
- T1036.004 Masquerade Task or Service
- T1036.005 Match Legitimate Resource Name or Location
- T1041 Exfiltration Over C2 Channel
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1048.003 Exfiltration Over Unencrypted Non-C2 Protocol
- T1049 System Network Connections Discovery
- T1053.005 Scheduled Task
- T1055.001 Dynamic-link Library Injection
- T1056.001 Keylogging
- T1057 Process Discovery
- T1059.001 PowerShell
- T1059.003 Windows Command Shell
- T1059.005 Visual Basic
- T1070 Indicator Removal
- T1070.003 Clear Command History
- T1070.004 File Deletion
- T1070.006 Timestomp
- T1071.001 Web Protocols
- T1074.001 Local Data Staging
- T1078 Valid Accounts
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1090.001 Internal Proxy
- T1090.002 External Proxy
- T1098 Account Manipulation
- T1102.002 Bidirectional Communication
- T1104 Multi-Stage Channels
- T1105 Ingress Tool Transfer
- T1106 Native API
- T1110.003 Password Spraying
- T1124 System Time Discovery
- T1132.001 Standard Encoding
- T1134.002 Create Process with Token
- T1140 Deobfuscate/Decode Files or Information
- T1189 Drive-by Compromise
- T1202 Indirect Command Execution
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1218 System Binary Proxy Execution
- T1218.005 Mshta
- T1218.011 Rundll32
- T1485 Data Destruction
- T1489 Service Stop
- T1491.001 Internal Defacement
- T1529 System Shutdown/Reboot
- T1542.003 Bootkit
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1547.009 Shortcut Modification
- T1553.002 Code Signing
- T1557.001 Name Resolution Poisoning and SMB Relay
- T1560 Archive Collected Data
- T1560.002 Archive via Library
- T1560.003 Archive via Custom Method
- T1561.001 Disk Content Wipe
- T1561.002 Disk Structure Wipe
- T1564.001 Hidden Files and Directories
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1566.003 Spearphishing via Service
- T1571 Non-Standard Port
- T1573.001 Symmetric Cryptography
- T1574.001 DLL
- T1574.013 KernelCallbackTable
- T1583.001 Domains
- T1583.006 Web Services
- T1584.004 Server
- T1585.001 Social Media Accounts
- T1585.002 Email Accounts
- T1587.001 Malware
- T1588.002 Tool
- T1588.004 Digital Certificates
- T1589.002 Email Addresses
- T1591 Gather Victim Org Information
- T1620 Reflective Code Loading
- T1680 Local Storage Discovery
- T1685 Disable or Modify Tools
- T1686.003 Windows Host Firewall
Software 26
- route
- netsh
- Responder
- Volgmer
- FALLCHILL
- Proxysvc
- Bankshot
- RATANKBA
- BADCALL
- HARDRAIN
- TYPEFRAME
- KEYMARBLE
- AuditCred
- RawDisk
- WannaCry
- HOPLIGHT
- HotCroissant
- Dacls
- Cryptoistic
- BLINDINGCAN
- Dtrack
- AppleJeus
- TAINTEDSCRIBE
- ECCENTRICBANDWAGON
- ThreatNeedle
- MagicRAT
Principal sources 1,294 reports
Ranked by how many of this actor's indicators each report brought in.
- 321x.com/L0Psec/status/2020850377801781319
- 313virustotal.com/gui/ip-address/95.169.180.198/relations
- 313virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0…
- 313virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b…
- 313virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
- 185x.com/dazhengzhang/status/1899776299725680975
- 185x.com/tayvano_/status/1899896814536712334
- 185virustotal.com/gui/ip-address/5.230.252.157/relations
Related groups 10
What the sources have in common — not a claim that these are the same actor. See the whole graph.
2 more in the relationship graph.
Timeline 5,380 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
Showing the 300 most recent of 5,380. Complete: G0032.json.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
microsoft.com/en-us/security/blog/2026/02/24/c2-devel…
141.94.148.37:1224 141.94.148.37:3333 141.94.148.39:1224 141.94.148.39:3333 151.80.76.64:1224 151.80.76.64:3333 51.255.9.164:1224 51.255.9.164:3333 54.39.43.119:1224 54.39.43.119:3333 -
microsoft.com/en-us/security/blog/2026/02/24/c2-devel…
141.94.148.35:1224 51.79.124.171:1224 54.39.43.114:1224 -
x.com/ishivtripathi/status/2084907438243991883 · virustotal.com/gui/file/ab65cef60fc097c2a9fb03a7855c9c… · virustotal.com/gui/file/225d7482772a26e4236d91cae51197… · virustotal.com/gui/file/5c9bc15e2db6ca97ff325159d6c07f…
domain logkit-tau.vercel.app ipv4 66.45.225.94:1244 ipv4 66.45.225.94:1245 ipv4 66.45.225.94:1246 -
x.com/KseProso/status/2084984281785389166
blackskydev.org -
blog.fox-it.com/2025/09/01/three-lazarus-rats-coming-fo… · blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-tha… · virustotal.com/gui/file/d8de31bcaf5b9ebb99bef36244b0ab…
kerajaanmoshi.xyz -
x.com/tuckner/status/2065140621497561236 · gist.github.com/danslo/1778c3bf30d65967db2d680727cbc89d
domain 166-88-54-158.nip.io domain desarrollolab.com domain uk-link84.luckylink.top domain vs.desarrollolab.com domain vscodeextensions.desarrollolab.com ipv4 23.27.13.43:27017 ipv4 23.27.13.43:443 ipv4 23.27.13.43:8888 ipv4 23.27.20.187:27107 ipv4 23.27.20.187:443 ipv4 23.27.20.187:8888 url http://23.27.13.43 url http://23.27.20.187 -
x.com/malwrhunterteam/status/2064325045938274… · x.com/malwrhunterteam/status/2069411902774472… · virustotal.com/gui/file/c7a24e1fc68b7233e1c93c02409e94… · virustotal.com/gui/file/9d7576046152695728ead43e9752a1… · virustotal.com/gui/file/70f732e98634c3f887d84ba8acb1ee… · virustotal.com/gui/file/51e1f3a97629e8db50ca1f9a0b68c0… · virustotal.com/gui/file/322b2eb4e4d61ec6a746e3da421e8f… · virustotal.com/gui/file/068505fab1dc1b784ddc845c9eeeba… · virustotal.com/gui/file/0988384971ae7a2213793eab632112… · virustotal.com/gui/file/3ad42864371905aa4618ab74dcd67b… · virustotal.com/gui/file/4524b20f1d3c3299c66058e9bcba6f… · virustotal.com/gui/file/cc92280557b399ec9271af08c5b6f5…
iploglab.store -
x.com/KirkDerpca/status/2065027462761787802 · panther.com/blog/tracking-an-ottercookie-infosteale…
95.216.118.146:3000 -
x.com/2eroHunter/status/2059205570393997429 · virustotal.com/gui/file/163e4a72cbe392c073eddc60aee69d…
172-86-89-213.cprapid.com softwareupdate.online -
x.com/blackbigswan/status/2079687425757249884
domain everydaynodechecker-39143n.vercel.app ipv4 31.222.250.65:1244 ipv4 31.222.250.65:15152 -
x.com/zoomeye_team/status/1901822378348568825 · x.com/blackorbird/status/1993135605623218560 · socket.dev/blog/lazarus-strikes-npm-again-with-a-n… · gendigital.com/blog/insights/research/apt-cyber-allian… · app.validin.com/detail?find=L-Administrator&type=raw&re… · virustotal.com/gui/file/c6edbb0d733798e5e8168a9df2bcca…
138.201.220.225:1224 138.201.220.225:1245 -
x.com/nextronresearch/status/2079454428038406… · virustotal.com/gui/file/1aadea997fc4eda5a8a04e68f6e182… · virustotal.com/gui/file/c107419b6b4c793c92289f00cbb229…
api.avax-test.dev avax-test.dev -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
l3vywd.easypanel.host -
socradar.io/blog/dprk-clickfake-pylangghost-golangg…
domain api.sapia.us domain canditech.co domain canditech.ink domain canditech.net domain canditech.online domain canditech.org domain canditech.us domain canditech.xyz domain employ-check.com domain mettl.app domain mettl.us domain mettl.xyz domain nvidiadriver.net domain sapia.us domain szynergy.org domain tecmlny.com domain workbright.shop domain workbright.us domain y69.org domain zavnia.us domain ziggeo.tech ipv4 95.216.92.207:4000 ipv4 95.216.92.207:7777 ipv4 95.216.92.207:8080 -
x.com/malwrhunterteam/status/1991488257708945… · x.com/banthisguy9349/status/20125522201017386… · research.jfrog.com/post/hijacked-npm-vscode-tasks-blockcha… · checkmarx.com/zero-post/chainveil-a-malicious-npm-sup… · virustotal.com/gui/file/0a133d4b96fc7b750a7b2ac14c152b…
166.88.134.82:27107 166.88.4.2:27017 166.88.4.2:443 23.27.120.142:27017 23.27.120.142:443 23.27.20.143:27017 23.27.20.143:443 23.27.202.27:27017 23.27.202.27:443 45.249.90.214:27017 -
app.validin.com/detail?find=Node.js%20upload%20multiple… · app.validin.com/detail?find=VScode&type=raw&ref_id=689d…
66.235.175.96:1244 66.235.175.96:3000 -
x.com/malwrhunterteam/status/2064325045938274… · x.com/malwrhunterteam/status/2069411902774472… · virustotal.com/gui/file/c7a24e1fc68b7233e1c93c02409e94… · virustotal.com/gui/file/9d7576046152695728ead43e9752a1… · virustotal.com/gui/file/70f732e98634c3f887d84ba8acb1ee… · virustotal.com/gui/file/51e1f3a97629e8db50ca1f9a0b68c0… · virustotal.com/gui/file/322b2eb4e4d61ec6a746e3da421e8f… · virustotal.com/gui/file/068505fab1dc1b784ddc845c9eeeba… · virustotal.com/gui/file/0988384971ae7a2213793eab632112… · virustotal.com/gui/file/3ad42864371905aa4618ab74dcd67b… · virustotal.com/gui/file/4524b20f1d3c3299c66058e9bcba6f… · virustotal.com/gui/file/cc92280557b399ec9271af08c5b6f5…
assetslib.shop -
virustotal.com/gui/ip-address/82.29.157.117/relations · app.validin.com/detail?find=%3A%3A%3A%22keywords%22%3A%…
talynexistest.com -
virustotal.com/gui/ip-address/76.76.21.241/relations
rest-icon-provider.net -
x.com/banthisguy9349/status/20790774051138603… · virustotal.com/gui/file/41ee7ddb2be173686dc3a73a49b4e9…
cdn-static-icons.vercel.app rest-icon-configure.vercel.app rest-icon-moduler.vercel.app rest-icon-provider.link verceljs-kappa.vercel.app -
x.com/nextronresearch/status/2079118025236566…
rest-icon-helper.store -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
r4liyq.easypanel.host -
x.com/KfishNFT/status/2014379828787494923 · x.com/g0njxa/status/2014800328105894004 · radar.securityalliance.org/vs-code-tasks-abuse-by-contagious-inter… · abstract.security/blog/contagious-interview-tracking-the-… · virustotal.com/gui/file/60914b8df5b5d64070f71ef1381749… · virustotal.com/gui/file/6be45e165de60b61e9b7cb9e1f9b72… · virustotal.com/gui/file/c226eb59cf696a85ed7134b57f12d8…
162.0.239.85:3000 -
virustotal.com/gui/ip-address/104.21.39.124/relations
digital-skill-assessment.com -
elastic.co/security-labs/contagious-interview-malw…
domain controller.rightwidth.dev domain file.rightwidth.dev domain hohoho.rightwidth.dev domain huhuhu.rightwidth.dev domain ldb.rightwidth.dev domain rightwidth.dev domain upload.rightwidth.dev ipv4 188.40.64.61:5000 ipv4 188.40.64.61:7777 ipv4 195.26.248.212:7000 ipv4 195.26.248.212:8081 ipv4 195.26.248.212:8443 -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
domain 91.90.121.87.sslip.io domain talent-telusdigital.com ipv4 216.126.236.64:3000 ipv4 216.126.236.64:7777 ipv4 216.126.236.64:8888 ipv4 91.90.121.87:443 -
x.com/L0Psec/status/2077401458505359828 · virustotal.com/gui/file/795034792aa705f730dd498c51cbd6…
vscode-address-checking-mo.vercel.app vscode-check-mo1.vercel.app vscode-clone.vercel.app vscode-ip-addess-checking.vercel.app vscode-ip-address-checking-ten.vercel.app vscode-ipaddress-checking-nine.vercel.app vscode-ipaddress-checking.vercel.app vscode-ipchecking.vercel.app vscode-setting-6-28.vercel.app vscode-settings-8140-self.vercel.app -
kl4r10n.tech/blog/dprk-new-malware
144.172.108.236:2000 144.172.108.236:3000 144.172.108.236:5918 -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
x8qiup.easypanel.host -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
o1xyc6.easypanel.host -
x.com/KfishNFT/status/2014379828787494923 · x.com/g0njxa/status/2014800328105894004 · radar.securityalliance.org/vs-code-tasks-abuse-by-contagious-inter… · abstract.security/blog/contagious-interview-tracking-the-… · virustotal.com/gui/file/60914b8df5b5d64070f71ef1381749… · virustotal.com/gui/file/6be45e165de60b61e9b7cb9e1f9b72… · virustotal.com/gui/file/c226eb59cf696a85ed7134b57f12d8…
65.108.27.116:3000 -
microsoft.com/en-us/security/blog/2026/02/24/c2-devel…
147.124.216.103:1224 147.124.217.204:1224 151.80.205.187:1224 167.114.215.75:1224 192.99.204.154:1224 51.178.11.177:1224 51.178.11.181:1224 54.39.43.117:1224 -
virustotal.com/gui/file/a1e96380809fa22b8ba0c9377e52b7…
bitensor.xyz -
x.com/malwrhunterteam/status/2074106725951590… · virustotal.com/gui/ip-address/144.172.110.53/relations · tria.ge/260706-qky96abw2q/behavioral1
domain callsdk.online domain coalink.support domain team.business.in domain web02eu.live domain webcamsdk-update.online ipv4 144.172.110.53:3000 -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
cameradriver.pro cctxtools.com hiring-intellipro.com sysdoctor.org zonelitho.com -
x.com/veryseriouseng/status/20741320071063597…
http://5.175.184.52 -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
domain app.vereoy.com domain cameradriverupdates.com domain paxos-apply.com domain vereoy.com ipv4 144.208.127.165:3000 -
x.com/zoomeye_team/status/1901822378348568825 · x.com/blackorbird/status/1993135605623218560 · socket.dev/blog/lazarus-strikes-npm-again-with-a-n… · gendigital.com/blog/insights/research/apt-cyber-allian… · app.validin.com/detail?find=L-Administrator&type=raw&re… · virustotal.com/gui/file/c6edbb0d733798e5e8168a9df2bcca…
95.216.64.240:1224 95.216.64.240:1245 -
x.com/skocherhan/status/2074059180256739719
knockri.us -
x.com/nextronresearch/status/2074031725764633…
http://104.243.41.127 -
x.com/banthisguy9349/status/20741297936926887…
figuermarkets.com -
x.com/veryseriouseng/status/20719811117233316… · x.com/banthisguy9349/status/20724926977646429…
http://62.33.223.164 -
x.com/veryseriouseng/status/20727353101784024… · ossprey.com/blog/how-ossprey-uncovered-a-large-scal…
domain uaaidmission.org ipv4 103.35.188.48:3000 ipv4 103.35.188.48:5000 ipv4 138.201.140.23:4553 ipv4 139.60.162.62:3000 ipv4 139.60.162.62:5000 ipv4 144.172.104.196:7431 ipv4 144.172.104.196:7436 ipv4 144.172.112.214:3000 ipv4 144.172.112.214:5000 ipv4 147.124.202.210:1244 ipv4 147.124.202.213:1244 ipv4 162.120.17.8:3000 ipv4 162.120.17.8:5000 ipv4 216.126.224.168:7101 ipv4 216.126.224.168:7106 ipv4 216.126.225.104:3000 ipv4 216.126.225.104:5000 ipv4 216.126.237.71:4891 ipv4 216.126.237.71:4892 ipv4 216.126.237.71:4893 ipv4 216.126.237.71:4894 ipv4 216.126.237.71:4895 ipv4 216.126.237.71:4896 ipv4 216.126.237.71:4897 ipv4 216.126.237.71:4898 ipv4 31.207.47.71:3000 ipv4 31.207.47.71:5000 ipv4 38.92.47.157:1244 ipv4 38.92.47.175:1244 ipv4 45.140.167.218:1224 ipv4 45.59.160.215:3000 ipv4 45.59.163.198:1244 ipv4 66.248.205.172:3000 ipv4 66.248.205.172:5000 ipv4 66.248.205.172:8000 ipv4 95.216.37.186:3000 ipv4 95.216.37.186:5000 url http://147.189.172.105 url http://216.126.225.83 -
x.com/veryseriouseng/status/20715258993132835… · x.com/veryseriouseng/status/20715185529101517… · research.jfrog.com/post/rollup-polyfill-masquerading
ipv4 216.126.236.244:4801 ipv4 216.126.236.244:4806 ipv4 216.126.236.244:4808 ipv4 216.126.236.244:4809 url http://144.172.100.204 url http://144.172.101.178 url http://144.172.103.75 url http://144.172.105.92 url http://144.172.110.72 url http://144.172.114.159 url http://144.172.114.56 url http://144.172.115.235 url http://144.172.116.19 url http://144.172.116.67 url http://144.172.117.86 url http://144.172.89.227 url http://144.172.91.252 url http://144.172.93.69 url http://144.172.95.14 url http://144.172.97.203 url http://144.172.97.67 url http://144.172.98.156 url http://144.172.98.170 url http://153.75.91.138 url http://216.126.224.195 url http://216.126.225.84 url http://216.126.227.161 url http://216.126.227.187 url http://216.126.229.172 url http://216.126.236.138 url http://216.126.236.244 url http://216.126.237.112 url http://216.126.237.86 -
microsoft.com/en-us/security/blog/2026/02/24/c2-devel…
198.135.49.65:1224 216.250.252.245:1224 -
x.com/KirkDerpca/status/2065027462761787802 · panther.com/blog/tracking-an-ottercookie-infosteale…
cloudflare-prevention.vercel.app -
x.com/L0Psec/status/2020850377801781319 · virustotal.com/gui/ip-address/95.169.180.198/relations · virustotal.com/gui/file/41c24510d95fcafc4cc3c31bebccc0… · virustotal.com/gui/file/867dd37ad635536cd9396c15944b9b… · virustotal.com/gui/file/cf33cc4237492b0660698f25548d67…
savannahpos.co.ke -
microsoft.com/en-us/security/blog/2026/02/24/c2-devel…
198.135.51.233:1224 216.250.249.179:1224 216.250.251.187:1224 -
x.com/zoomeye_team/status/1901822378348568825 · x.com/blackorbird/status/1993135605623218560 · socket.dev/blog/lazarus-strikes-npm-again-with-a-n… · gendigital.com/blog/insights/research/apt-cyber-allian… · app.validin.com/detail?find=L-Administrator&type=raw&re… · virustotal.com/gui/file/c6edbb0d733798e5e8168a9df2bcca…
69.197.164.135:1224 69.197.164.135:1245 -
trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-… · trendmicro.com/content/dam/trendmicro/global/en/resear… · research.jfrog.com/post/hijacked-npm-vscode-tasks-blockcha…
ipv4 166.88.134.62:10000 ipv4 166.88.134.62:2000 ipv4 166.88.134.62:443 url http://154.91.0.196 url http://166.88.134.62 url http://198.105.127.210 -
x.com/malwrhunterteam/status/2064325045938274… · x.com/malwrhunterteam/status/2069411902774472… · virustotal.com/gui/file/c7a24e1fc68b7233e1c93c02409e94… · virustotal.com/gui/file/9d7576046152695728ead43e9752a1… · virustotal.com/gui/file/70f732e98634c3f887d84ba8acb1ee… · virustotal.com/gui/file/51e1f3a97629e8db50ca1f9a0b68c0… · virustotal.com/gui/file/322b2eb4e4d61ec6a746e3da421e8f… · virustotal.com/gui/file/068505fab1dc1b784ddc845c9eeeba… · virustotal.com/gui/file/0988384971ae7a2213793eab632112… · virustotal.com/gui/file/3ad42864371905aa4618ab74dcd67b… · virustotal.com/gui/file/4524b20f1d3c3299c66058e9bcba6f… · virustotal.com/gui/file/cc92280557b399ec9271af08c5b6f5…
domain githelper.store ipv4 104.194.153.144:8085 ipv4 104.194.153.144:8086 ipv4 104.194.153.144:8087 -
opensourcemalware.com/blog/latest-contagious-interview-malwar…
ip-api-check-nine.vercel.app test-assesment-kk37hvtef-mahs-projects-03bae667.vercel.app test-assesment-self.vercel.app vscode-checking-ip-address.vercel.app vscode-setup.vercel.app -
x.com/v0lundr_/status/2065375317682696560
theapp.tobeht.com tobeht.com -
x.com/v0lundr_/status/2065375317682696560
aigtech.dev -
x.com/smica83/status/2067587696134889943 · virustotal.com/gui/file/7dc3082d2fb8f7fadf4de5155405fb… · virustotal.com/gui/file/d78e925950df009a753f9eb193c853…
17.docsend.store 3.143.24.91.sslip.io 5l.securemypc.xyz admin0.docsend.store ag.centoservices.cz centoservices.cz cloud.medipoint.mccprod.site cms.docsend.store dg.novaplayer.online docview.ink eduflex-eu.org ftp.teams-meets.com gorodmechty.ddns.net jk.theworldofluck.site mccprod.site novaplayer.online securemypc.xyz sp-plus-api.mccprod.site teams-live.cam teams-live.work teams-meet.co teams-meeting.in teams-meets.com teams-meets.online teams-meets.us.com theworldofluck.site -
x.com/blackorbird/status/2066892874839687418 · roman.pt/posts/linkedin-backdoor
rest-icon-handler.store -
x.com/L0Psec/status/2066540844006375831 · virustotal.com/gui/file/95fdd6fe3c222a51a8038d8340e433… · virustotal.com/gui/file/1a3146e3df64507fd9ab933f7ca395…
domain driverhubpro.net ipv4 45.95.186.237:8000 url http://45.95.186.237 -
x.com/tuckner/status/2065140621497561236 · gist.github.com/danslo/1778c3bf30d65967db2d680727cbc89d
ipv4 166.88.54.158:27107 ipv4 166.88.54.158:443 ipv4 166.88.54.158:8888 url http://166.88.54.158 -
x.com/KirkDerpca/status/2065027462761787802 · panther.com/blog/tracking-an-ottercookie-infosteale…
cloudflare1.vercel.app datasecure-service.vercel.app -
x.com/KfishNFT/status/2014379828787494923 · x.com/g0njxa/status/2014800328105894004 · radar.securityalliance.org/vs-code-tasks-abuse-by-contagious-inter… · abstract.security/blog/contagious-interview-tracking-the-… · virustotal.com/gui/file/60914b8df5b5d64070f71ef1381749… · virustotal.com/gui/file/6be45e165de60b61e9b7cb9e1f9b72… · virustotal.com/gui/file/c226eb59cf696a85ed7134b57f12d8…
vscode-ip-address-checking.vercel.app vscode-ip-checking-nine.vercel.app -
x.com/L0Psec/status/2036098821059461256 · x.com/L0Psec/status/2049158325372125450 · virustotal.com/gui/file/4291da6d5461c51ff0f852ca40a557… · virustotal.com/gui/file/c2fe5b1d2c4cef27ab22fa8bc960a7… · virustotal.com/gui/file/a6d2f0c3892b443d022d4c77835a85…
oxdo.xyz -
x.com/L0Psec/status/2036098821059461256 · x.com/L0Psec/status/2049158325372125450 · virustotal.com/gui/file/4291da6d5461c51ff0f852ca40a557… · virustotal.com/gui/file/c2fe5b1d2c4cef27ab22fa8bc960a7… · virustotal.com/gui/file/a6d2f0c3892b443d022d4c77835a85…
admin.rohapowers.com alqaflah.com -
proofpoint.com/us/blog/threat-insight/dont-fear-repo-u…
domain alphanonega.org · 48 more in this batch, in the JSON
Further reading 1,305
- attack.mitre.org/groups/G0032
- blogs.jpcert.or.jp/en/2025/03/classifying-lazaruss-subgrou…
- blogs.microsoft.com/on-the-issues/2017/12/19/microsoft-face…
- cloud.google.com/blog/topics/threat-intelligence/mapping…
- cloud.google.com/blog/topics/threat-intelligence/north-k…
- home.treasury.gov/news/press-releases/sm774
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- web.archive.org/web/20160226161828/https://www.operatio…
- web.archive.org/web/20210723190317/https://adversary.cr…
- secureworks.com/about/press/media-alert-secureworks-dis…
- us-cert.gov/ncas/alerts/TA17-164A
- us-cert.gov/ncas/analysis-reports/AR19-100A
- virustotal.com/gui/file/91eaf215be336eae983d069de16630…
- twitter.com/ShadowChasing1/status/14129346652923166…
- welivesecurity.com/en/eset-research/gotta-fly-lazarus-targ…
- twitter.com/tiresearch1/status/1784118099278741797
- virustotal.com/gui/ip-address/212.85.29.150/relations
- twitter.com/felixaime/status/1280053007036624896
- virustotal.com/gui/file/ac7b6ca73207db6ec6d4af2632a7c8…
- socket.dev/blog/contagious-interview-campaign-esca…
- otx.alienvault.com/pulse/5eb2fabf6c26a287f705ca20
- virustotal.com/gui/ip-address/45.63.1.46/relations
- x.com/abh1sek/status/2044260573324685605
- virustotal.com/gui/file/ab65cef60fc097c2a9fb03a7855c9c…
- virustotal.com/gui/ip-address/45.61.136.133/relations
- x.com/superducktoes/status/2059302288552812818
- virustotal.com/gui/file/a9b3bc337043c04f529b2c19b3e33d…
- asec.ahnlab.com/en/56405
- twitter.com/fr0s7_/status/1695012576600498679
- twitter.com/h2jazi/status/1509206625701220356
- twitter.com/cyberwar_15/status/1264353716930412544
- twitter.com/kyleehmke/status/1184120287199223808
- socket.dev/blog/north-korean-contagious-interview-…
- twitter.com/Bank_Security/status/1107543887462064128
- virustotal.com/gui/file/cf2e793eac702b70865c79d550cea3…
- securelist.com/operation-applejeus/87553
- twitter.com/pkalnai/status/1489269982814949382
- blog.talosintelligence.com/lazarus-collectionrat
- otx.alienvault.com/pulse/5f4d20e8d417f271a62e0aeb
- app.any.run/tasks/01497f45-7fba-4356-bbdc-4270e51c2…
1,265 more, and the report behind every indicator, in G0032.json.