INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Malware via Spear-Phishing Attacks

| 2026-08-30 20:30 LOW HIGH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A malicious link was found in a larger pulse, four months prior to the reported incident on August 29th, 2026. The identified entity behind this incident is Credential Dumping. This attack affected Spain as it targeted individuals with malicious links that led to credential dumping, specifically utilizing techniques such as T1060, T1003, and T1057. The attackers exploited vulnerabilities in software like Akamai App And Api Protector, using a URI http://[IOC HIDDEN • LOGIN REQUIRED]/ that resulted in a 400 Bad Request status or a 404 NOT FOUND response from https://sami-normal-sg.capcutapi.com.
Technical Mitigations AI-generated
• Block or hunt for invalid URLs, specifically those with a '404 NOT FOUND' status. • Use the Akamai App And Api Protector to patch vulnerabilities in software. • Detect and prevent write operations using ASCII text strings.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

51f5fc••••••••••••••••••••••••••••••••••
5006c9••••••••••••••••••••••••••••••••••
3c96c9••••••••••••••••••••••••••••••••••
f4eda0••••••••••••••••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
7f7d10••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
b82bfb••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
147169••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
c6a537••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
wi•••••.open
na•••••.online
ti•••••.com
og•••••.me
23.58.•••.•••
5a34cb••••••••••••••••••••••••••
20f011••••••••••••••••••••••••••
f4fe1c••••••••••••••••••••••••••
f65c72••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
ES
Incident Timeline
‎August 29th, 2026
Threat actors used phishing emails to dump credentials from a company's employee accounts on the dark web.
‎2026/08/30
Threat actors used a combination of techniques, including data exfiltration and malware execution, to dump credentials from multiple sources.
organisation Credential Dumping
Intelligence Sources
AlienVault OTX 2026-08-30
Credential Dumping AlienVault OTX