C&CMembers
C&C

Lazarus Label Rides on Thin Evidence: Old Domains, Shared Certs

A Lazarus Group-tagged indicator set offers almost no malicious signal — 29 hashes with no metadata and fifteen network indicators at 0-1/91 detections. The only concrete pattern is infrastructural: decades-old Namecheap domains reissuing certificates in lockstep, and two Incapsula CDN IPs sharing Imperva's multi-tenant certificate.

Aug 10, 2026, 22:37 (UTC+9)Last seenAug 10, 2026Severity82ByCTX TeamActorLazarus GroupHastati GroupIOC44RegionsDE

A cluster of internet infrastructure carrying a Lazarus Group label arrived this month with almost nothing behind it: 29 file hashes with no signer, no size, no threat classification attached to any of them, and fifteen network indicators that sit at 0 or 1 detection out of 91 security engines, with zero community votes either way.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence