Threat Actor 🇰🇵 North Korea

Lazarus Group

Also known as: Operation DarkSeoul · Dark Seoul · Hidden Cobra · Hastati Group · Andariel · Unit 121 · Bureau 121 · NewRomanic Cyber Army Team · Bluenoroff · Subgroup: Bluenoroff · Group 77 · Labyrinth Chollima · Operation Troy · Operation GhostSecret · Operation AppleJeus · APT38 · APT 38 · Stardust Chollima · Whois Hacking Team · Zinc · Appleworm · Nickel Academy · APT-C-26 · NICKEL GLADSTONE · COVELLITE · ATK3 · G0032 · ATK117 · G0082 · Citrine Sleet · DEV-0139 · DEV-1222 · Diamond Sleet · ZINC · Sapphire Sleet · COPERNICIUM · TA404 · Lazarus group · BeagleBoyz · Moonstone Sleet · Black Artemis

Since 2009, HIDDEN COBRA actors have leveraged their capabilities to target and compromise a range of victims; some intrusions have resulted in the exfiltration of data while others have been disruptive in nature. Commercial reporting has referred to this activity as Lazarus Group and Guardians of Peace. Tools and capabilities used by HIDDEN COBRA actors include DDoS botnets, keyloggers, remote access tools (RATs), and wiper malware. Variants of malware and tools used by HIDDEN COBRA actors include Destover, Duuzer, and Hangman.

Indicators of Compromise 60

Domain enveil[.]online Domain envell[.]xyz Domain hwsrv-798836[.]hostwindsdns[.]com Domain npmjs[.]store Domain us[.]zoom[.]06webin[.]us Domain uxtramine[.]org Email rchaitm[@]gmail[.]com Filename %TEMP%\rust-setup-launch.vbs Filename %TEMP%\rust-setup.ps1 Filename /tmp/rust-setup Filename OneScreenCapture64.dll Filename Release_GetInfoPlugin_x64.dll Filename Release_PvPlugin_x64.dll Filename Temp.b Filename core.js Filename libmupdf.dll Filename main.exe Filename package.bat Filename package.db Filename rust-crate_0.1.0 Filename rust-crate_0.2.0 Filename rust-crate_0.3.0 Filename rust-crate_0.4.0 GitHub Repo impacket/impacket GitHub User alchemy_john_mac GitHub User impacket SHA-1 f22e3e01e38bcdf001f0d15a2dbfdec5a1cf8eff SHA-1 f4767ad92cb61401fd69139cade563501c39b991 SHA-1 fc0fdb978eac72f4484b48db058e4473f1bc516e SHA-1 ff7e20cf642346bf893f1eca808df82035bb53d0 SHA-256 0098273 SHA-256 2014d09c7ded74d89c885b5f11693865224116f1b25df9330e61fe528f419d73 SHA-256 24604384b0e748ada07923630b3d037489e696284a98c4409fb9b6763565571f SHA-256 25ad700976873c76af785cb99b33c48db7df8b81f21d1e9e06b3676b9a9373ae SHA-256 61198155da51b838772eecf5bfaac6cbc4dcc388dccc56658fc28a8e831b34d4 SHA-256 b5c1b5b0763a8809a644a8f92224653f0aca623a98eecc714d27f74b80fbe436 SHA-256 d2a74db6b9c900ad29a81432af72eee8ed4e22bf61055e7e8f7a5f1a33778277 IP 142[.]111[.]77[.]196 IP 216[.]74[.]123[.]126 IP 23[.]254[.]165[.]112:443 IP 23[.]254[.]165[.]112:9089 IP 23[.]254[.]167[.]107:443 Package aovine Package append-only-vec@0.1.9 Package arone Package aronenao Package arrayref@0.3.10 Package axios Package chalk Package debug Package harthat-api Package harthat-hash Package internment@0.8.7 Package proc-macro-en Package proc-macro1 Package tinymember Package typo-crypto Registry User John Registry User dtolney Registry User nagasiren978

MITRE ATT&CK TTPs 53

T1001
Data Obfuscation
Command And Control
T1003
OS Credential Dumping
Credential Access
T1018
Remote System Discovery
Discovery
T1021.001
Remote Desktop Protocol
Lateral Movement
T1021.002
SMB/Windows Admin Shares
Lateral Movement
T1021.004
SSH
Lateral Movement
T1021.006
Windows Remote Management
Lateral Movement
T1027
Obfuscated Files or Information
Defense Evasion
T1029
Scheduled Transfer
Exfiltration
T1036.005
Match Legitimate Name or Location
Defense Evasion
T1040
Network Sniffing
Credential Access
T1053.005
Scheduled Task
Execution
T1055
Process Injection
Defense Evasion
T1057
Process Discovery
Discovery
T1059
Command and Scripting Interpreter
Execution
T1059.001
PowerShell
Execution
T1059.003
Windows Command Shell
Execution
T1068
Exploitation for Privilege Escalation
Privilege Escalation
T1070.001
Clear Windows Event Logs
Defense Evasion
T1070.004
File Deletion
Defense Evasion
T1070.006
Timestomp
Defense Evasion
T1071.001
Web Protocols
Command And Control
T1078
Valid Accounts
Defense Evasion
T1082
System Information Discovery
Discovery
T1083
File and Directory Discovery
Discovery
T1085
T1085
T1087
Account Discovery
Discovery
T1090
Proxy
Command And Control
T1098
Account Manipulation
Persistence
T1105
Ingress Tool Transfer
Command And Control
T1129
Shared Modules
Execution
T1133
External Remote Services
Persistence
T1134
Access Token Manipulation
Defense Evasion
T1190
Exploit Public-Facing Application
Initial Access
T1195.002
Compromise Software Supply Chain
Initial Access
T1203
Exploitation for Client Execution
Execution
T1204.002
Malicious File
Execution
T1210
Exploitation of Remote Services
Lateral Movement
T1218
System Binary Proxy Execution
Defense Evasion
T1218.011
Rundll32
Defense Evasion
T1480
Execution Guardrails
Defense Evasion
T1485
Data Destruction
Impact
T1486
Data Encrypted for Impact
Impact
T1495
Firmware Corruption
Impact
T1534
Internal Spearphishing
Lateral Movement
T1548
Abuse Elevation Control Mechanism
Privilege Escalation
T1557
Adversary-in-the-Middle
Credential Access
T1558
Steal or Forge Kerberos Tickets
Credential Access
T1566
Phishing
Initial Access
T1566.001
Spearphishing Attachment
Initial Access
T1566.002
Spearphishing Link
Initial Access
T1583
Acquire Infrastructure
Resource Development
T1610
Deploy Container
Defense Evasion

Source Articles

Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
A supply chain attack was conducted against the Rust ecosystem by compromising the maintainer account of widely used crates, including arrayref, internment, and append-only-vec. Malicious versions were published with a typosquatted dependency, proc-macro1, which executes a build script to download and run a second-stage payload. The payload acts as a backdoor, exfiltrating system information, enumerating browser login data, and enabling remote command execution, with infrastructure and TTPs showing significant overlap with DPRK-linked campaigns such as Mastra and UNC1069.
wiz
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
Multiple active threats were reported this week, including exploitation of critical vulnerabilities in VMware, Apple macOS, and GeoServer, as well as ongoing campaigns by state-linked actors. A suspected China-nexus APT exploited CVE-2026-59310 in VMware vCenter to deploy Babuk-derived ransomware, likely as a forensic distraction. The Lazarus Group leveraged a Windows zero-day (CVE-2026-68820) in a campaign dubbed Operation Dream Job, targeting aerospace and defense sectors. GeoServer faced active exploitation of a critical SQL injection flaw prior to patching. Additionally, new macOS malware Amnesia Stealer enables real-time browser hijacking via Chrome DevTools Protocol, stealing authenticated sessions and sensitive data.
hacker-news ·2w ago
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor Lazarus Group has exploited a Windows zero-day vulnerability, CVE-2026-68820, in the AFD.sys driver to escalate privileges to SYSTEM and deploy a new in-memory backdoor named Troy. The attack is part of Operation Dream Job, a long-running cyber espionage campaign using fake job offers on LinkedIn to lure victims into downloading trojanized software or opening malicious PDFs. Two infection chains were observed: one using DLL side-loading with the malicious libmupdf.dll and another via a trojanized SecurityPDF viewer that triggers payload execution upon detecting a specific marker in a PDF. The attackers also use compromised legitimate infrastructure, including WordPress, SharePoint, and vulnerable Roundcube servers (CVE-2025-49113), to host C2 communications and distribute the ForestTiger (ScoringMathTea) backdoor.
hacker-news ·3w ago
Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft's August 2026 security update addresses 398 vulnerabilities, including CVE-2026-68820, a Windows kernel driver zero-day under active exploitation for privilege escalation. The flaw exists in afd.sys and allows attackers with initial code execution to escalate to SYSTEM privileges. Check Point Research attributes the exploitation to the Lazarus Group in their 'Operation Dream Job' campaign. Four additional critical unauthenticated remote code execution flaws in Windows DNS Server, Windows Deployment Services, Microsoft QUIC, and HPC Pack are also patched but were not under active attack at release. The update also completes a SharePoint exploit chain by fixing CVE-2026-63520, the RCE component that, when combined with July's authentication bypass (CVE-2026-55040), enabled unauthenticated RCE.
hacker-news ·3w ago
Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days
Microsoft's August 2026 Patch Tuesday addresses 400 vulnerabilities, including three zero-days. One of these, CVE-2026-68820, was actively exploited in the wild by the North Korean threat actor Lazarus Group to elevate privileges and deploy a kernel-mode rootkit called FudModule. The other two zero-days, CVE-2026-62832 and CVE-2026-72971, were publicly disclosed but not confirmed as exploited. Check Point linked the exploitation of CVE-2026-68820 to Lazarus, highlighting ongoing targeting using local privilege escalation in Windows drivers.
bleeping-computer ·3w ago
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Gunra ransomware, a Conti-derived operation, has been actively targeting critical infrastructure sectors globally, including healthcare, financial services, and government facilities. The group exploits known vulnerabilities in Fortinet (CVE-2025-24472) and Schneider Electric (CVE-2024-5559) devices to gain initial access, then uses Impacket tools for lateral movement and credential dumping. Gunra employs a double extortion model, exfiltrating data before encryption, and has listed 51 victims on its leak site since April 2025, primarily in South Korea, Brazil, and Europe. The group has ties to affiliate programs, uses WhatsApp for negotiations, and has demonstrated advanced capabilities such as MFA bypass and session hijacking via SSL-VPN manipulation.
hacker-news ·3w ago
US and South Korea warn of Gunra ransomware targeting govt agencies
US and South Korean agencies issued a joint advisory warning of Gunra ransomware attacks targeting government and critical infrastructure organizations. The ransomware, first observed in April 2025, is derived from the leaked Conti source code and uses double extortion tactics. Gunra actors exploit vulnerabilities in Fortinet devices (CVE-2024-55591, CVE-2025-24472) and misconfigured SSH access on internet-facing systems to gain initial access, and have expanded operations through a ransomware-as-a-service (RaaS) model under the alias 'Golden Community'. The group has also recruited initial access brokers, including penetration testers, and has extended attacks to Linux environments since mid-2025.
bleeping-computer ·3w ago
Amazon identifies North Korean hacker group behind open-source supply chain attacks | AWS Security Blog
Amazon Threat Intelligence has identified a DPRK-linked threat actor behind multiple supply chain attacks on popular NPM packages including axios, debug, chalk, and typo-crypto. The actor used social engineering to gain access to maintainer accounts and published trojanized updates containing malicious code. These attacks leveraged post-install hooks, multi-stage payloads, and C2 infrastructure to deliver malware across thousands of downstream environments. The same actor is assessed to have tested their tradecraft in a smaller campaign via the typo-crypto package before escalating to higher-impact compromises. The group uses sophisticated evasion techniques including code obfuscation, environment detection to avoid sandboxes, and generative AI to produce convincing malicious packages.
static-urls
Amazon links Debug, Chalk NPM supply-chain attacks to North Korean hackers
Amazon has linked multiple npm supply-chain attacks to the North Korean threat actor Sapphire Sleet (also known as BlueNoroff and Stardust Chollima) with medium confidence. The attacks began in March 2025 with the compromise of the typo-crypto package, followed by the trojanization of widely used packages debug and chalk in September 2025, impacting an estimated 10% of cloud environments within two hours. In March 2026, the axios library—used by over 100 million developers weekly—was targeted, with malicious updates distributed after attackers socially engineered maintainers to gain access. The campaign used sophisticated tactics including delayed execution in real environments, multi-stage payloads, and 'slopsquatting' of AI-hallucinated package names to expand reach.
bleeping-computer ·4w ago
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
Amazon Threat Intelligence attributes the September 2025 compromise of the npm packages debug and chalk to the North Korean threat actor Sapphire Sleet, also linked to prior attacks on axios and typo-crypto. The attacks began with social engineering of maintainers, followed by malicious updates containing trojanized code. The debug and chalk incident involved a browser-side interceptor that hijacked cryptocurrency transactions by rewriting wallet addresses, while other campaigns used post-install hooks and command-and-control infrastructure. Amazon ties the campaigns together through shared tradecraft, code reuse, and overlapping C2 indicators, though some technical discrepancies exist in the evidence.
hacker-news ·4w ago