Skip to main content
← All Articles

Tag

#lazarus-group

7 articles

Advertisement

TH
HIGH
Threat Intel

CrowdStrike 2026 Financial Threat Report: Trends in Identity Exploitation

Analysis of the CrowdStrike 2026 Financial Services Threat Landscape Report, focusing on identity-based attacks, cloud risks, and adversary TTPs.

Runtime Rebel Intel
3 min read·May 15, 2026
TH
HIGH
Threat Intel

DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud

Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.

Runtime Rebel Intel
4 min read·Apr 16, 2026
SU
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read·Apr 6, 2026
SU
CRITICAL
Supply Chain

Axios npm Hijack Attempt: Detecting Social Engineering Tactics

North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.

Runtime Rebel Intel
3 min read·Apr 5, 2026
WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware
HIGH
Threat Intel

WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware

North Korean threat actor WaterPlum leverages VS Code tasks.json to automate StoatWaffle malware deployment during fraudulent developer recruitment campaigns.

Runtime Rebel Intel
4 min read·Mar 23, 2026
TH
HIGH
Threat Intel

TfL Data Breach and Avira Security Flaws: Weekly Threat Briefing

Analysis of the Transport for London breach affecting 10 million users, Avira antivirus security flaws, and North Korean cyber actor attribution.

Runtime Rebel Intel
3 min read·Mar 6, 2026
TH
HIGH
Threat Intel

Lazarus Group Targets U.S. Healthcare with Medusa Ransomware

North Korean Lazarus Group is targeting U.S. healthcare providers with Medusa ransomware, utilizing Dtrack malware for initial access and persistence.

Runtime Rebel Intel
4 min read·Feb 24, 2026