Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Study & Research - Hidden Cobra And DeltaCharlie: An Explainer
Study & Research

Hidden Cobra And DeltaCharlie: An Explainer

ISBuzz TeamBy ISBuzz TeamJune 19, 20174 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Tech Provider ABB Struck By Black Basta Ransomware Attacks
Tech Provider ABB Struck By Black Basta Ransomware Attacks
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The Department of Homeland Security (DHS) and the Federal Bureau of Investigation (FBI) released a technical alert on Hidden Cobra, the malicious cyber activities by the North Korean government. North Korea’s DDoS botnet infrastructure is also sometimes referred to as Hidden Cobra.

The alert provides technical details on the tools and infrastructure, including IP addresses associated with DeltaCharlie, a malware variant used to manage North Korea’s distributed denial of service (DDoS) botnet infrastructure. Also listed were indicators of compromise, malware descriptions, network signatures, and host-based rules that network admins can use to detect activity conducted by the North Korean government on their networks.

The technical alert encourages users and administrators who detect the use of Hidden Cobra custom tools to report such activities to the DHS or FBI.

Imperva Incapsula has put together some frequently asked questions and is continuing to monitor the situation.

  1. What is Hidden Cobra?
  2. The U.S. Government refers to the malicious cyber activity by the North Korean government as Hidden Cobra.

Activities now identified as Hidden Cobra began in 2009. These activities include exploits by threat actors on victims in the public and private sector, theft of data and disruption of website availability.

  1. What is DeltaCharlie and how does it differ from Hidden Cobra?
  2. According to the US-CERT report, DeltaCharlie is the malware used to infect machines converting them to “zombie” bots. Infected bots collectively become a botnet that is controlled by threat actors.

The DeltaCharlie malware was discovered by Novetta in its 2016 Operation Blockbuster Malware Report. There is evidence that the malware may have been present on victims’ networks for a significant period.

  1. What are the capabilities of Hidden Cobra and DeltaCharlie?
  2. According to Novetta’s report, threat actors use Hidden Cobra tools and capabilities such as DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware.

Hidden Cobra threat actors use DeltaCharlie as a DDoS tool. DeltaCharlie has been used in several exploits since it was first reported.

  1. How does DeltaCharlie launch DDoS attacks?
  2. DeltaCharlie can launch DNS, NTP and character generation protocol DDoS attacks by operating on victims’ systems as a svchost-based service (a system that hosts multiple Windows services in Windows NT). It can download executable files, change its configuration, update its own binaries, terminate its own processes, and activate and terminate denial of service attacks.
  3. How do the Lazarus Group and Guardians of Peace relate to all this?
  4. According to the US-CERT report, Hidden Cobra has been previously reported as the Lazarus Group and Guardians of Peace.

The Lazarus Group was first reported in Operation Blockbuster by Novetta. It has been active since 2007 and has been conducting attacks as recently as May 2017. It is most well-known for its high-profile attack on Sony Pictures Entertainment in 2014.

On November 24, 2014, a post on Reddit reported that Sony Pictures had been hacked. A group identified itself as the Guardians of Peace and hacked into the Sony network, leaving it unavailable for days. The Guardians of Peace accessed information on employees, email and unreleased films. Guardians of Peace claimed it had been in the Sony network for a year before being discovered.

How to Mitigate DDoS Attacks

The US-CERT report suggests how network admins can defend their systems.

Patch applications and operating systems – Update software and patches frequently and download updates only from trusted vendor sites.

Whitelist applications – Use whitelisting to allow only specified programs to run and block malicious software.

Restrict administrative privileges – Reduce privileges to fit a user’s role. Keep administrators in privileged tiers and limit access to other tiers.

Segment networks and segregate them into security zones – By segmenting networks, admins can help protect sensitive information and critical services, and minimise damage from network perimeter breaches.

Validate input – Input validation can protect against security gaps in web applications and potentially block attacks such as SQL injection, cross-site scripting, and command injection.

Use stringent file reputation settings – Keep the file reputation lists of your anti-virus software at the most aggressive setting allowable. This can help prevent a wide range of untrustworthy code from gaining control.

Leverage firewalls – Firewalls keep your network less likely from being attacked. Web application firewalls can block data and applications from certain IPs, while allowing necessary data through.

[su_box title=”About Imperva” style=”noise” box_color=”#336588″][short_info id=’60217′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}