Last seven days
- First activity
- Aug 14, 2026
- Last activity
- Aug 14, 2026
- Feed role
- C2
- Host form
- 0 IP / 3 hostnames
C2 tracking
Derp observations, rolling seven-day window
Reported operators
Our initial analysis of malware disclosed in the BadCyber blog hinted at the involvement of the 'Lazarus' threat actor... The filename srservice.chm is consistent with the method in which a known Lazarus toolkit module constructs CHM and HLP file names... It's worth noting that both parts of the shellcode load the APIs similarly to all other tools from the Lazarus toolset.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.