logo

The Infostealer to APT Pipeline: How Lazarus Group Hijacked a Yemen Disinformation Network

ID: fe3d71b9-c89e-51d0-b48c-731fe075324c

STIX ID: report--fe3d71b9-c89e-51d0-b48c-731fe075324c

Feed Name: infostealers.com

Threat Score
85/100

Date Published: 2025-12-12

Date Updated: 2026-06-07

Author: InfoStealers

...
...

**Infostealer to APT Pipeline:** Hudson Rock investigates how a RedLine-infested Windows 10 machine in Ta’izz, Yemen, exposed admin credentials for several fake-news WordPress sites (e.g., alnagm-press.com, azal-press.com, gulfnaw.com), enabling the Lazarus Group (APT38) to hijack these trusted domains and repurpose them as command-and-control and reconnaissance infrastructure for broader malicious operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.