Skip to main content
← Threat Intel

Threat Actor

Lazarus Group

34 tracked articles · Wikipedia profile

  • CRITICAL 2
  • HIGH 28
  • MEDIUM 4
DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft
HIGH
Threat Intel

DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft

North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.

Runtime Rebel Intel
3 min read · Jul 30, 2026
BlueNoroff Zoom Phishing Kit Targets Crypto Wallets
HIGH
Threat Intel

BlueNoroff Zoom Phishing Kit Targets Crypto Wallets

BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.

Runtime Rebel Intel
4 min read · Jul 24, 2026
North Korean Actors Use SVG Steganography to Deliver OtterCookie
HIGH
Threat Intel

North Korean Actors Use SVG Steganography to Deliver OtterCookie

North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.

Runtime Rebel Intel
5 min read · Jul 17, 2026
PolinRider: North Korean Hackers Push 108 Malicious Packages
HIGH
Supply Chain

PolinRider: North Korean Hackers Push 108 Malicious Packages

Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.

Runtime Rebel Intel
4 min read · Jul 4, 2026
SU
HIGH
Supply Chain

North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages

Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.

Runtime Rebel Intel
3 min read · Jun 20, 2026
Chinese and North Korean APT Activity Surges Across APAC Markets
MEDIUM
Threat Intel

Chinese and North Korean APT Activity Surges Across APAC Markets

Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.

Runtime Rebel Intel
3 min read · Jun 11, 2026
VU
CRITICAL
Vulnerabilities

CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus

Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.

Runtime Rebel Intel
4 min read · May 21, 2026
North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026
HIGH
Threat Intel

North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026

North Korean threat actors are projected to be responsible for 76% of all cryptocurrency stolen by 2026, utilizing sophisticated methods for large-scale heists.

Runtime Rebel Intel
4 min read · May 2, 2026
MA
HIGH
Malware

Redtail Malware Exploiting CVE-2024-3400: Technical Analysis

Analysis of the Libredtail variant exploiting Palo Alto Networks CVE-2024-3400 to deploy crypto-miners and establish rootkit persistence.

Runtime Rebel Intel
3 min read · Apr 30, 2026
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
HIGH
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
4 min read · Apr 29, 2026
VU
CRITICAL
Vulnerabilities

Windows Kernel LPE CVE-2024-21338: Lazarus Group Exploits Zero-Day

CISA adds CVE-2024-21338 to KEV catalog after Lazarus Group exploited the Windows Kernel vulnerability to deploy rootkits and bypass security controls.

Runtime Rebel Intel
3 min read · Apr 29, 2026
BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware
HIGH
Threat Intel

BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware

BlueNoroff leverages AI avatars and stolen video to compromise crypto executives via fake Zoom calls and the Hidden Risk macOS malware family.

Runtime Rebel Intel
4 min read · Apr 29, 2026
Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks
HIGH
Threat Intel

Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks

An analysis of Lazarus Group's persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.

Runtime Rebel Intel
5 min read · Apr 28, 2026
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
HIGH
Threat Intel

DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories

DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…

Runtime Rebel Intel
5 min read · Apr 22, 2026
TH
HIGH
Threat Intel

KelpDAO $290 Million Heist Linked to North Korea’s Lazarus Group

KelpDAO suffers a $290 million crypto-heist attributed to the North Korean Lazarus Group, highlighting ongoing threats to DeFi liquid restaking protocols.

Runtime Rebel Intel
4 min read · Apr 21, 2026
TH
HIGH
Threat Intel

DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud

Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.

Runtime Rebel Intel
4 min read · Apr 16, 2026
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
HIGH
Supply Chain

North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI

North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.

Runtime Rebel Intel
4 min read · Apr 8, 2026
DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea
MEDIUM
Threat Intel

DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea

North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.

Runtime Rebel Intel
4 min read · Apr 6, 2026
SU
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read · Apr 6, 2026
DPRK Social Engineering Behind $285 Million Drift Hack: Analysis
HIGH
Threat Intel

DPRK Social Engineering Behind $285 Million Drift Hack: Analysis

A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.

Runtime Rebel Intel
3 min read · Apr 5, 2026
SU
HIGH
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read · Apr 5, 2026
TH
MEDIUM
Threat Intel

Defending Against Rogue IP KVMs: Detection and Mitigation Strategies

Discover how threat actors use rogue IP KVMs to bypass EDR and gain persistent remote access, including technical detection and mitigation strategies.

Runtime Rebel Intel
3 min read · Mar 24, 2026
WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware
HIGH
Threat Intel

WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware

North Korean threat actor WaterPlum leverages VS Code tasks.json to automate StoatWaffle malware deployment during fraudulent developer recruitment campaigns.

Runtime Rebel Intel
4 min read · Mar 23, 2026
TH
HIGH
Threat Intel

Bitrefill Attributes Cyberattack to North Korean Lazarus Group

Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.

Runtime Rebel Intel
3 min read · Mar 19, 2026