The Infostealer to APT Pipeline: How Lazarus Group Hijacked a Yemen Disinformation Network
ID: fe3d71b9-c89e-51d0-b48c-731fe075324c
STIX ID: report--fe3d71b9-c89e-51d0-b48c-731fe075324c
Feed Name: infostealers.com
Threat Score
**Infostealer to APT Pipeline:** Hudson Rock investigates how a RedLine-infested Windows 10 machine in Ta’izz, Yemen, exposed admin credentials for several fake-news WordPress sites (e.g., alnagm-press.com, azal-press.com, gulfnaw.com), enabling the Lazarus Group (APT38) to hijack these trusted domains and repurpose them as command-and-control and reconnaissance infrastructure for broader malicious operations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
