C&CMembers
C&C

2006 MyDoom Worm Resurfaces Tagged as Lazarus Espionage Tool

A threat feed attributes a high-severity, Lazarus-linked entry to a two-decade-old mass-mailing worm masquerading as services.exe. Of 35 bundled hashes, only one carries any data — and its evidence points to commodity malware, not nation-state tradecraft.

Aug 27, 2026, 06:30 (UTC+9)Last seenAug 27, 2026Severity82ByCTX TeamActorLazarus GroupHastati GroupIOC48

A file that has been circulating since the summer of 2006 just resurfaced inside a threat feed carrying a severity score of 82, a confidence score of 85, and an attribution line naming Lazarus Group — the North Korea-aligned operation with roughly twenty tracked aliases. The artefact behind that label is not a bespoke implant.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence