Skip to main content
← All Articles

Tag

#Lazarus Group

19 articles

Advertisement

TH
CRITICAL
Threat Intel

North Korean APT Bridges Air Gaps with New Malware Suite

North Korean threat actors utilize malicious LNK files and specialized USB propagation tools to compromise air-gapped networks. Analysis and defense guide.

Runtime Rebel Intel
4 min read·Mar 2, 2026
North Korean Malicious npm Packages: Detecting Contagious Interview
HIGH
Supply Chain

North Korean Malicious npm Packages: Detecting Contagious Interview

North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.

Runtime Rebel Intel
3 min read·Mar 2, 2026
TH
HIGH
Threat Intel

Fake Recruiters Deploy Malware via Malicious Coding Challenges

North Korean threat actors are targeting software developers with fake job offers and malicious coding tests to deploy malware on developer workstations.

Runtime Rebel Intel
3 min read·Feb 27, 2026
Next.js Supply Chain Attacks: North Korean Actors Target Developers
HIGH
Supply Chain

Next.js Supply Chain Attacks: North Korean Actors Target Developers

North Korean state-sponsored actors leverage malicious Next.js repositories and fake job interviews to compromise developers' systems for persistent access and espionage.

Runtime Rebel Intel
4 min read·Feb 25, 2026
Lazarus Group Shifts to Medusa Ransomware & Multi-Tool Attacks
HIGH
Threat Intel

Lazarus Group Shifts to Medusa Ransomware & Multi-Tool Attacks

North Korea's Lazarus Group now employs Medusa ransomware, Comebacker backdoor, Blindingcan RAT, and Infohook info stealer in recent attacks, signaling an evolving

Runtime Rebel Intel
4 min read·Feb 25, 2026
Lazarus Group Deploys Medusa Ransomware in Global Healthcare Attacks
HIGH
Threat Intel

Lazarus Group Deploys Medusa Ransomware in Global Healthcare Attacks

Lazarus Group (Diamond Sleet) targets Middle Eastern entities and U.S. healthcare with Medusa ransomware, according to Symantec and Carbon Black reports.

Runtime Rebel Intel
3 min read·Feb 24, 2026
ID
HIGH
Identity & Access

Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure

Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.

Runtime Rebel Intel
2 min read·Feb 23, 2026