logo

HIDDEN COBRA – North Korea’s DDoS Botnet Infrastructure | US-CERT

ID: 488899e0-0afc-43cb-9407-e5f3951d1a58

STIX ID: report--488899e0-0afc-43cb-9407-e5f3951d1a58

Threat Score

85/100

Uploaded: 2026-08-15

Published Date: 2017-06-15

Last Modified Date: 2017-06-15

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
US‑CERT Alert TA17‑164A (HIDDEN COBRA) details North Korean government cyber operations using the DeltaCharlie DDoS botnet to target media, aerospace, financial, and critical infrastructure sectors worldwide; the alert provides technical analysis, IOCs (CSV/STIX), network signatures, YARA rules, CVE references, and recommended mitigation and response actions for network defenders.