TI Mindmap HUB
Threat Intelligence Report

Hunting Lazarus Part III: The Infrastructure That Was Too Perfect

📅 February 6, 2026 📰 redasgard.com 🔍 3 CVE(s) referenced

In investigating Lazarus Group’s “Contagious Interview” campaign, we discovered a second, highly advanced malware family and mapped nearly 20 perfectly hardened C2 servers—only to find so many anomalies that we now believe the infrastructure is likely a sophisticated honeypot or counter-intelligence operation designed to hunt the hunters.

vendor
CVE-2017-16026, CVE-2020-7699, CVE-2022-24999

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle