Skip to main content
← All Articles

Tag

#Lazarus Group

19 articles

Advertisement

VU
CRITICAL
Vulnerabilities

CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus

Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.

Runtime Rebel Intel
4 min read·May 21, 2026
North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026
HIGH
Threat Intel

North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026

North Korean threat actors are projected to be responsible for 76% of all cryptocurrency stolen by 2026, utilizing sophisticated methods for large-scale heists.

Runtime Rebel Intel
4 min read·May 2, 2026
MA
HIGH
Malware

Redtail Malware Exploiting CVE-2024-3400: Technical Analysis

Analysis of the Libredtail variant exploiting Palo Alto Networks CVE-2024-3400 to deploy crypto-miners and establish rootkit persistence.

Runtime Rebel Intel
3 min read·Apr 30, 2026
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
CRITICAL
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
3 min read·Apr 29, 2026
BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware
HIGH
Threat Intel

BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware

BlueNoroff leverages AI avatars and stolen video to compromise crypto executives via fake Zoom calls and the Hidden Risk macOS malware family.

Runtime Rebel Intel
4 min read·Apr 29, 2026
Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks
CRITICAL
Threat Intel

Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks

An analysis of Lazarus Group's persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.

Runtime Rebel Intel
5 min read·Apr 28, 2026
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
CRITICAL
Threat Intel

DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories

DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply

Runtime Rebel Intel
5 min read·Apr 22, 2026
North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI
CRITICAL
Supply Chain

North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI

North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.

Runtime Rebel Intel
3 min read·Apr 8, 2026
DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea
HIGH
Threat Intel

DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea

North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.

Runtime Rebel Intel
3 min read·Apr 6, 2026
SU
CRITICAL
Supply Chain

Stardust Chollima Compromises Axios npm Package

Technical analysis of the Stardust Chollima supply chain attack targeting the Axios npm package to exfiltrate developer credentials and data.

Runtime Rebel Intel
4 min read·Apr 2, 2026
TH
HIGH
Threat Intel

Bitrefill Attributes Cyberattack to North Korean Lazarus Group

Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.

Runtime Rebel Intel
3 min read·Mar 19, 2026
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs
MEDIUM
Threat Intel

OFAC Sanctions DPRK IT Worker Network Funding WMD Programs

US Treasury sanctions North Korea's IT worker network used to fund WMD programs. Learn how these actors use fake identities and how to secure remote hiring.

Runtime Rebel Intel
4 min read·Mar 18, 2026