
C&CMembers
C&C2006 MyDoom Worm Resurfaces Tagged as Lazarus Espionage Tool
A threat feed attributes a high-severity, Lazarus-linked entry to a two-decade-old mass-mailing worm masquerading as services.exe. Of 35 bundled hashes, only one carries any data — and its evidence points to commodity malware, not nation-state tradecraft.
Aug 27, 2026, 06:30 (UTC+9)Last seenAug 27, 2026Severity82ByCTX TeamActorLazarus GroupHastati GroupIOC48
A file that has been circulating since the summer of 2006 just resurfaced inside a threat feed carrying a severity score of 82, a confidence score of 85, and an attribution line naming Lazarus Group — the North Korea-aligned operation with roughly twenty tracked aliases. The artefact behind that label is not a bespoke implant.
Members only
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to readSource: CTX Threat Intelligence