logo

Lazarus_Group__2021__Commonly_Known_Tools_Used_by_Lazarus_-_JPCERT_CC_Eyes_JPCERT_Coordination_Center_official_Blog.pdf

ID: 07061f20-cc01-45a7-97e7-926e10ebdfc9

STIX ID: report--07061f20-cc01-45a7-97e7-926e10ebdfc9

Threat Score

82/100

Uploaded: 2026-08-15

Published Date: 2021-01-25

Last Modified Date: 2021-01-25

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This JPCERT blog post catalogs commonly used tools and techniques attributed to the Lazarus (Hidden Cobra) threat actor, covering utilities for lateral movement (AdFind, SMBMap, Responder-Windows), credential and data theft (XenArmor tools, WinRAR usage), and remote access/forensics tools (TightVNC, ProcDump, tcpdump, wget), and provides example file hashes as IoCs while noting these tools are widely available and may be used legitimately.