
Lazarus Label Rides on Thin Evidence: Old Domains, Shared Certs
A Lazarus Group-tagged indicator set offers almost no malicious signal — 29 hashes with no metadata and fifteen network indicators at 0-1/91 detections. The only concrete pattern is infrastructural: decades-old Namecheap domains reissuing certificates in lockstep, and two Incapsula CDN IPs sharing Imperva's multi-tenant certificate.
A cluster of internet infrastructure carrying a Lazarus Group label arrived this month with almost nothing behind it: 29 file hashes with no signer, no size, no threat classification attached to any of them, and fifteen network indicators that sit at 0 or 1 detection out of 91 security engines, with zero community votes either way.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read