Lazarus_Group__2021__Commonly_Known_Tools_Used_by_Lazarus_-_JPCERT_CC_Eyes_JPCERT_Coordination_Center_official_Blog.pdf
ID: 07061f20-cc01-45a7-97e7-926e10ebdfc9
STIX ID: report--07061f20-cc01-45a7-97e7-926e10ebdfc9
Threat Score
82/100
Uploaded: 2026-08-15
Published Date: 2021-01-25
Last Modified Date: 2021-01-25
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This JPCERT blog post catalogs commonly used tools and techniques attributed to the Lazarus (Hidden Cobra) threat actor, covering utilities for lateral movement (AdFind, SMBMap, Responder-Windows), credential and data theft (XenArmor tools, WinRAR usage), and remote access/forensics tools (TightVNC, ProcDump, tcpdump, wget), and provides example file hashes as IoCs while noting these tools are widely available and may be used legitimately.
