HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructure | US-CERT
ID: 488899e0-0afc-43cb-9407-e5f3951d1a58
STIX ID: report--488899e0-0afc-43cb-9407-e5f3951d1a58
Threat Score
85/100
Uploaded: 2026-08-15
Published Date: 2017-06-15
Last Modified Date: 2017-06-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
US‑CERT Alert TA17‑164A (HIDDEN COBRA) details North Korean government cyber operations using the DeltaCharlie DDoS botnet to target media, aerospace, financial, and critical infrastructure sectors worldwide; the alert provides technical analysis, IOCs (CSV/STIX), network signatures, YARA rules, CVE references, and recommended mitigation and response actions for network defenders.
