Skip to content

Lazarus

Profile source: Mallory opens in a new tab

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Aug 14, 2026
Last activity
Aug 14, 2026
Feed role
C2
Host form
0 IP / 3 hostnames

Leading locations

  • FI2
  • DE1

Leading providers

  • Hetzner Online GmbH2
  • Hostinger International Limited1

Infrastructure traits

  • Hosting 3
  • Anycast 1

Reported operators

Threat actors

1 named in public reporting
Lazarus

Our initial analysis of malware disclosed in the BadCyber blog hinted at the involvement of the 'Lazarus' threat actor... The filename srservice.chm is consistent with the method in which a known Lazarus toolkit module constructs CHM and HLP file names... It's worth noting that both parts of the shellcode load the APIs similarly to all other tools from the Lazarus toolset.

MITRE ATT&CK

Lazarus in ATT&CK

1 distinct techniques

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.