<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Lazarus Group</title><description>Cybersecurity articles tagged #Lazarus Group on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Microsoft August 2026 Patch Tuesday: 398 Flaws and Zero-Day</title><link>https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/microsoft-august-2026-patch-tuesday-398-flaws-and-zero-day</guid><description>Microsoft patches 398 flaws in August 2026, including an actively exploited Windows kernel driver zero-day and four critical RCE vulnerabilities.</description><pubDate>Wed, 12 Aug 2026 01:05:21 GMT</pubDate><category>Windows</category><category>SharePoint</category><category>Zero-Day</category><category>Lazarus Group</category><category>CVE-2026-68820</category></item><item><title>DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft</title><link>https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</guid><description>North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.</description><pubDate>Thu, 30 Jul 2026 21:11:51 GMT</pubDate><category>macOS</category><category>Lazarus Group</category><category>Malvertising</category><category>Cryptocurrency</category><category>DPRK</category></item><item><title>BlueNoroff Zoom Phishing Kit Targets Crypto Wallets</title><link>https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluenoroff-zoom-phishing-kit-targets-crypto-wallets</guid><description>BlueNoroff uses a custom phishing kit to profile crypto wallets before delivering malware through impersonated Zoom and Microsoft Teams platforms.</description><pubDate>Fri, 24 Jul 2026 17:39:06 GMT</pubDate><category>BlueNoroff</category><category>Lazarus Group</category><category>Cryptocurrency Theft</category><category>ClickFix</category><category>Phishing</category></item><item><title>North Korean Actors Use SVG Steganography to Deliver OtterCookie</title><link>https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-actors-use-svg-steganography-to-deliver-ottercookie</guid><description>North Korean threat actors are hiding OtterCookie malware in SVG flag images within fake coding tests to target developers and steal cryptocurrency.</description><pubDate>Fri, 17 Jul 2026 17:13:52 GMT</pubDate><category>Lazarus Group</category><category>OtterCookie</category><category>Contagious Interview</category><category>Steganography</category><category>Node Js</category><category>Infostealer</category></item><item><title>PolinRider: North Korean Hackers Push 108 Malicious Packages</title><link>https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</guid><description>Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.</description><pubDate>Sat, 04 Jul 2026 13:37:02 GMT</pubDate><category>PolinRider</category><category>Lazarus Group</category><category>NPM</category><category>Chrome Web Store</category><category>Supply Chain Attack</category><category>North Korea</category></item><item><title>North Korean Sapphire Sleet Compromises 140+ Mastra AI npm Packages</title><link>https://runtimerebel.com/blog/north-korean-sapphire-sleet-compromises-140-mastra-ai-npm-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-sapphire-sleet-compromises-140-mastra-ai-npm-packages</guid><description>Microsoft attributes the Mastra AI supply chain attack to Sapphire Sleet (BlueNoroff), involving 140+ malicious npm packages targeting AI developers.</description><pubDate>Sat, 20 Jun 2026 16:38:13 GMT</pubDate><category>Sapphire Sleet</category><category>BlueNoroff</category><category>Mastra AI</category><category>NPM</category><category>Supply Chain Attack</category><category>Lazarus Group</category></item><item><title>Chinese and North Korean APT Activity Surges Across APAC Markets</title><link>https://runtimerebel.com/blog/chinese-and-north-korean-apt-activity-surges-across-apac-markets</link><guid isPermaLink="true">https://runtimerebel.com/blog/chinese-and-north-korean-apt-activity-surges-across-apac-markets</guid><description>Chinese and North Korean threat groups are intensifying operations in Asia-Pacific, impacting regional economies and targeting financial institutions for profit.</description><pubDate>Thu, 11 Jun 2026 09:41:37 GMT</pubDate><category>Lazarus Group</category><category>Asia Pacific</category><category>Cyber Espionage</category><category>Financial Crime</category><category>APT</category></item><item><title>CVE-2024-21338: Microsoft Defender Zero-Day Exploited by Lazarus</title><link>https://runtimerebel.com/blog/cve-2024-21338-microsoft-defender-zero-day-exploited-by-lazarus</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2024-21338-microsoft-defender-zero-day-exploited-by-lazarus</guid><description>Microsoft patches two zero-day vulnerabilities in Defender and SmartScreen exploited by Lazarus Group for privilege escalation and malware delivery.</description><pubDate>Thu, 21 May 2026 09:15:26 GMT</pubDate><category>CVE-2024-21338</category><category>CVE-2024-21412</category><category>Lazarus Group</category><category>Microsoft Defender</category><category>Zero-Day</category></item><item><title>North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026</title><link>https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</guid><description>North Korean threat actors are projected to be responsible for 76% of all cryptocurrency stolen by 2026, utilizing sophisticated methods for large-scale heists.</description><pubDate>Sat, 02 May 2026 00:49:12 GMT</pubDate><category>North Korea</category><category>Cryptocurrency Theft</category><category>Lazarus Group</category><category>Cybercrime</category><category>Financial Crime</category><category>Nation State APT</category></item><item><title>Redtail Malware Exploiting CVE-2024-3400: Technical Analysis</title><link>https://runtimerebel.com/blog/redtail-malware-exploiting-cve-2024-3400-technical-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/redtail-malware-exploiting-cve-2024-3400-technical-analysis</guid><description>Analysis of the Libredtail variant exploiting Palo Alto Networks CVE-2024-3400 to deploy crypto-miners and establish rootkit persistence.</description><pubDate>Thu, 30 Apr 2026 08:53:37 GMT</pubDate><category>CVE-2024-3400</category><category>Redtail</category><category>GlobalProtect</category><category>Cryptominer</category><category>Lazarus Group</category></item><item><title>AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus</title><link>https://runtimerebel.com/blog/ai-generated-npm-supply-chain-attack-dprk-exploits-claude-opus</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-npm-supply-chain-attack-dprk-exploits-claude-opus</guid><description>North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.</description><pubDate>Wed, 29 Apr 2026 16:38:11 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>NPM</category><category>Malware</category><category>Claude Opus</category></item><item><title>Windows Kernel LPE CVE-2024-21338: Lazarus Group Exploits Zero-Day</title><link>https://runtimerebel.com/blog/windows-kernel-lpe-cve-2024-21338-lazarus-group-exploits-zero-day</link><guid isPermaLink="true">https://runtimerebel.com/blog/windows-kernel-lpe-cve-2024-21338-lazarus-group-exploits-zero-day</guid><description>CISA adds CVE-2024-21338 to KEV catalog after Lazarus Group exploited the Windows Kernel vulnerability to deploy rootkits and bypass security controls.</description><pubDate>Wed, 29 Apr 2026 12:41:40 GMT</pubDate><category>CVE-2024-21338</category><category>Lazarus Group</category><category>Windows Kernel</category><category>CISA KEV</category><category>Rootkit</category><category>Privilege Escalation</category></item><item><title>BlueNoroff Exploits Fake Zoom Meetings to Deploy macOS Malware</title><link>https://runtimerebel.com/blog/bluenoroff-exploits-fake-zoom-meetings-to-deploy-macos-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/bluenoroff-exploits-fake-zoom-meetings-to-deploy-macos-malware</guid><description>BlueNoroff leverages AI avatars and stolen video to compromise crypto executives via fake Zoom calls and the Hidden Risk macOS malware family.</description><pubDate>Wed, 29 Apr 2026 08:53:57 GMT</pubDate><category>BlueNoroff</category><category>Lazarus Group</category><category>Hidden Risk</category><category>macOS Malware</category><category>Cryptocurrency</category></item><item><title>Lazarus Group&apos;s $2B+ Crypto Theft: Defending Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</guid><description>An analysis of Lazarus Group&apos;s persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.</description><pubDate>Tue, 28 Apr 2026 16:47:53 GMT</pubDate><category>Lazarus Group</category><category>DPRK</category><category>Cryptocurrency Theft</category><category>Supply Chain Attack</category><category>Financial Cybercrime</category><category>APT</category></item><item><title>DPRK&apos;s &apos;Contagious Interview&apos; Spreads RATs via Dev Repositories</title><link>https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</guid><description>DPRK threat actors are employing a &apos;contagious interview&apos; scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…</description><pubDate>Wed, 22 Apr 2026 20:27:05 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>Fake Job Scam</category><category>RAT</category><category>Software Supply Chain</category><category>Social Engineering</category><category>Developer Compromise</category></item><item><title>KelpDAO $290 Million Heist Linked to North Korea’s Lazarus Group</title><link>https://runtimerebel.com/blog/kelpdao-290-million-heist-linked-to-north-koreas-lazarus-group</link><guid isPermaLink="true">https://runtimerebel.com/blog/kelpdao-290-million-heist-linked-to-north-koreas-lazarus-group</guid><description>KelpDAO suffers a $290 million crypto-heist attributed to the North Korean Lazarus Group, highlighting ongoing threats to DeFi liquid restaking protocols.</description><pubDate>Tue, 21 Apr 2026 00:44:39 GMT</pubDate><category>Lazarus Group</category><category>KelpDAO</category><category>DeFi</category><category>North Korea</category><category>Crypto Heist</category></item><item><title>DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud</title><link>https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</guid><description>Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.</description><pubDate>Thu, 16 Apr 2026 08:40:47 GMT</pubDate><category>DPRK</category><category>Laptop Farm</category><category>Insider Threat</category><category>Identity Theft</category><category>Lazarus Group</category></item><item><title>North Korean Hackers Distribute 1,700 Malicious Packages via npm and PyPI</title><link>https://runtimerebel.com/blog/north-korean-hackers-distribute-1700-malicious-packages-via-npm-and-pypi</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-hackers-distribute-1700-malicious-packages-via-npm-and-pypi</guid><description>North Korean threat actors expand the Contagious Interview campaign, deploying 1,700 malicious packages across npm, PyPI, Go, and Rust ecosystems.</description><pubDate>Wed, 08 Apr 2026 08:32:04 GMT</pubDate><category>Contagious Interview</category><category>Lazarus Group</category><category>Supply Chain Attack</category><category>NPM</category><category>PyPI</category><category>Malware</category></item><item><title>DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea</title><link>https://runtimerebel.com/blog/dprk-hackers-abuse-github-infrastructure-for-c2-in-south-korea</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-hackers-abuse-github-infrastructure-for-c2-in-south-korea</guid><description>North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.</description><pubDate>Mon, 06 Apr 2026 20:17:41 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>GitHub C2</category><category>South Korea</category><category>LNK</category><category>PowerShell</category></item><item><title>North Korean Social Engineering Targets Node.js Maintainers</title><link>https://runtimerebel.com/blog/north-korean-social-engineering-targets-node-js-maintainers</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-social-engineering-targets-node-js-maintainers</guid><description>North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.</description><pubDate>Mon, 06 Apr 2026 12:24:38 GMT</pubDate><category>Lazarus Group</category><category>NPM</category><category>Social Engineering</category><category>Node Js</category><category>North Korea</category></item><item><title>DPRK Social Engineering Behind $285 Million Drift Hack: Analysis</title><link>https://runtimerebel.com/blog/dprk-social-engineering-behind-285-million-drift-hack-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-social-engineering-behind-285-million-drift-hack-analysis</guid><description>A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.</description><pubDate>Sun, 05 Apr 2026 20:11:07 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>Drift Protocol</category><category>Social Engineering</category><category>Solana</category><category>Cryptocurrency Theft</category></item><item><title>Axios npm Hijack Attempt: Detecting Social Engineering Tactics</title><link>https://runtimerebel.com/blog/axios-npm-hijack-attempt-detecting-social-engineering-tactics</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-hijack-attempt-detecting-social-engineering-tactics</guid><description>North Korean threat actors targeted an Axios maintainer with a fake Microsoft Teams fix, highlighting critical risks to open-source supply chains.</description><pubDate>Sun, 05 Apr 2026 00:41:54 GMT</pubDate><category>Axios</category><category>NPM</category><category>Lazarus Group</category><category>Social Engineering</category><category>Supply Chain Security</category></item><item><title>Defending Against Rogue IP KVMs: Detection and Mitigation Strategies</title><link>https://runtimerebel.com/blog/defending-against-rogue-ip-kvms-detection-and-mitigation-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-against-rogue-ip-kvms-detection-and-mitigation-strategies</guid><description>Discover how threat actors use rogue IP KVMs to bypass EDR and gain persistent remote access, including technical detection and mitigation strategies.</description><pubDate>Tue, 24 Mar 2026 16:30:53 GMT</pubDate><category>IP KVM</category><category>Lazarus Group</category><category>Remote Access Fraud</category><category>Hardware Security</category></item><item><title>WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware</title><link>https://runtimerebel.com/blog/waterplum-abuses-vs-code-tasks-to-deploy-stoatwaffle-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/waterplum-abuses-vs-code-tasks-to-deploy-stoatwaffle-malware</guid><description>North Korean threat actor WaterPlum leverages VS Code tasks.json to automate StoatWaffle malware deployment during fraudulent developer recruitment campaigns.</description><pubDate>Mon, 23 Mar 2026 20:17:05 GMT</pubDate><category>Stoatwaffle</category><category>Waterplum</category><category>Visual Studio Code</category><category>North Korea</category><category>Lazarus Group</category></item><item><title>Bitrefill Attributes Cyberattack to North Korean Lazarus Group</title><link>https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</guid><description>Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.</description><pubDate>Thu, 19 Mar 2026 20:16:23 GMT</pubDate><category>Lazarus Group</category><category>BlueNoroff</category><category>Bitrefill</category><category>Cryptocurrency</category><category>APT</category><category>North Korea</category></item><item><title>OFAC Sanctions DPRK IT Worker Network Funding WMD Programs</title><link>https://runtimerebel.com/blog/ofac-sanctions-dprk-it-worker-network-funding-wmd-programs</link><guid isPermaLink="true">https://runtimerebel.com/blog/ofac-sanctions-dprk-it-worker-network-funding-wmd-programs</guid><description>US Treasury sanctions North Korea&apos;s IT worker network used to fund WMD programs. Learn how these actors use fake identities and how to secure remote hiring.</description><pubDate>Wed, 18 Mar 2026 20:15:49 GMT</pubDate><category>DPRK</category><category>OFAC</category><category>Lazarus Group</category><category>Sanctions</category><category>IT Worker Scheme</category></item><item><title>TfL Data Breach and Avira Security Flaws: Weekly Threat Briefing</title><link>https://runtimerebel.com/blog/tfl-data-breach-and-avira-security-flaws-weekly-threat-briefing</link><guid isPermaLink="true">https://runtimerebel.com/blog/tfl-data-breach-and-avira-security-flaws-weekly-threat-briefing</guid><description>Analysis of the Transport for London breach affecting 10 million users, Avira antivirus security flaws, and North Korean cyber actor attribution.</description><pubDate>Fri, 06 Mar 2026 16:21:41 GMT</pubDate><category>Data Breach</category><category>Avira Antivirus</category><category>Lazarus Group</category><category>Tfl Breach</category><category>APT</category></item><item><title>North Korean APT Bridges Air Gaps with New Malware Suite</title><link>https://runtimerebel.com/blog/north-korean-apt-bridges-air-gaps-with-new-malware-suite</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-apt-bridges-air-gaps-with-new-malware-suite</guid><description>North Korean threat actors utilize malicious LNK files and specialized USB propagation tools to compromise air-gapped networks. Analysis and defense guide.</description><pubDate>Mon, 02 Mar 2026 12:18:34 GMT</pubDate><category>Lazarus Group</category><category>Air Gapped</category><category>LNK Malware</category><category>North Korea</category><category>USB Propagation</category></item><item><title>North Korean Malicious npm Packages: Detecting Contagious Interview</title><link>https://runtimerebel.com/blog/north-korean-malicious-npm-packages-detecting-contagious-interview</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-malicious-npm-packages-detecting-contagious-interview</guid><description>North Korean actors published 26 malicious npm packages using Pastebin as a C2 dead drop resolver in a new Contagious Interview campaign iteration.</description><pubDate>Mon, 02 Mar 2026 12:18:05 GMT</pubDate><category>NPM</category><category>Lazarus Group</category><category>Contagious Interview</category><category>Supply Chain Attack</category><category>Pastebin</category><category>C2</category><category>Node Js</category></item><item><title>Fake Recruiters Deploy Malware via Malicious Coding Challenges</title><link>https://runtimerebel.com/blog/fake-recruiters-deploy-malware-via-malicious-coding-challenges</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-recruiters-deploy-malware-via-malicious-coding-challenges</guid><description>North Korean threat actors are targeting software developers with fake job offers and malicious coding tests to deploy malware on developer workstations.</description><pubDate>Fri, 27 Feb 2026 12:18:39 GMT</pubDate><category>Lazarus Group</category><category>North Korea</category><category>Social Engineering</category><category>Malicious Coding Challenges</category><category>Cryptocurrency</category><category>Trojanized Software</category></item><item><title>Next.js Supply Chain Attacks: North Korean Actors Target Developers</title><link>https://runtimerebel.com/blog/next-js-supply-chain-attacks-north-korean-actors-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/next-js-supply-chain-attacks-north-korean-actors-target-developers</guid><description>North Korean state-sponsored actors leverage malicious Next.js repositories and fake job interviews to compromise developers&apos; systems for persistent access and espionage.</description><pubDate>Wed, 25 Feb 2026 20:16:34 GMT</pubDate><category>Next Js</category><category>Software Supply Chain Attack</category><category>North Korea</category><category>Lazarus Group</category><category>Developers</category><category>Fake Job Scams</category><category>Persistent Access</category><category>Malware</category></item><item><title>Lazarus Group Shifts to Medusa Ransomware &amp; Multi-Tool Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-shifts-to-medusa-ransomware-multi-tool-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-shifts-to-medusa-ransomware-multi-tool-attacks</guid><description>North Korea&apos;s Lazarus Group now employs Medusa ransomware, Comebacker backdoor, Blindingcan RAT, and Infohook info stealer in recent attacks, signaling an evolving…</description><pubDate>Wed, 25 Feb 2026 04:43:37 GMT</pubDate><category>Lazarus Group</category><category>Medusa Ransomware</category><category>Comebacker</category><category>Blindingcan RAT</category><category>Infohook</category><category>North Korea</category><category>Ransomware</category><category>APT</category></item><item><title>Lazarus Group Targets U.S. Healthcare with Medusa Ransomware</title><link>https://runtimerebel.com/blog/lazarus-group-targets-u-s-healthcare-with-medusa-ransomware</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-targets-u-s-healthcare-with-medusa-ransomware</guid><description>North Korean Lazarus Group is targeting U.S. healthcare providers with Medusa ransomware, utilizing Dtrack malware for initial access and persistence.</description><pubDate>Tue, 24 Feb 2026 12:23:39 GMT</pubDate><category>Lazarus Group</category><category>Medusa Ransomware</category><category>Dtrack</category><category>Apt38</category><category>Healthcare Security</category></item><item><title>Lazarus Group Deploys Medusa Ransomware in Global Healthcare Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-deploys-medusa-ransomware-in-global-healthcare-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-deploys-medusa-ransomware-in-global-healthcare-attacks</guid><description>Lazarus Group (Diamond Sleet) targets Middle Eastern entities and U.S. healthcare with Medusa ransomware, according to Symantec and Carbon Black reports.</description><pubDate>Tue, 24 Feb 2026 12:21:18 GMT</pubDate><category>Lazarus Group</category><category>Medusa Ransomware</category><category>Diamond Sleet</category><category>Pompilus</category><category>Healthcare Security</category><category>North Korea</category></item><item><title>Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure</title><link>https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</guid><description>Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.</description><pubDate>Mon, 23 Feb 2026 16:26:29 GMT</pubDate><category>DPRK</category><category>Identity Theft</category><category>Remote Work Fraud</category><category>Insider Threat</category><category>Lazarus Group</category></item></channel></rss>