APTMembers
APT

Lazarus-Tagged Feed's Only Real Evidence Is a MyDoom-Era Worm

A record attributed to Lazarus Group with severity 82 and confidence 85 rests on a single detailed artifact: a 59KB MyDoom-lineage email worm dropped under a randomized Windows filename. The ten IPs and eleven domains surrounding it mostly resolve to shared CDN fabric and unrelated corporate address space, not attacker infrastructure.

Aug 19, 2026, 14:40 (UTC+9)Last seenAug 19, 2026Severity82ByCTX TeamActorLazarus GroupHastati GroupIOC54RegionsDE

A Windows binary classified as worm.mydoom/emailworm (fdeacb79…) — flagged by 66 of 76 engines and carrying the popular names "mydoom," "emailworm," and "amfu" — is the only file in this record that comes with any forensic detail at all. Of 33 catalogued file hashes tied to the package, 32 are bare values: no type, no size, no detection count, nothing.

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence