home.social

#lazarus — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lazarus, aggregated by home.social.

fetched live
  1. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  2. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  3. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  4. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  5. Ein #Sicherheitsforscher hat wohl fast zwei Jahre lang unbemerkt die Systeme nordkoreanischer Hackergruppen wie #Lazarus mitgelesen.

    Zentrale Erkenntnis: Die Cyberkriminellen attackieren oft nicht die Zielfirmen direkt, sondern kompromittieren IT-#Dienstleister, die in die Systeme mehrerer Kunden eingebunden sind.

    Eine einzige erfolgreiche Übernahme öffnet damit oft #Root-Zugänge zu Servern und Cloud-Umgebungen zahlreicher Unternehmen auf einen Schlag:

    wired.com/story/a-security-pro #cybersecurity

  6. Ein #Sicherheitsforscher hat wohl fast zwei Jahre lang unbemerkt die Systeme nordkoreanischer Hackergruppen wie #Lazarus mitgelesen.

    Zentrale Erkenntnis: Die Cyberkriminellen attackieren oft nicht die Zielfirmen direkt, sondern kompromittieren IT-#Dienstleister, die in die Systeme mehrerer Kunden eingebunden sind.

    Eine einzige erfolgreiche Übernahme öffnet damit oft #Root-Zugänge zu Servern und Cloud-Umgebungen zahlreicher Unternehmen auf einen Schlag:

    wired.com/story/a-security-pro #cybersecurity

  7. 📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign

    Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...

    🔗 cyber.netsecops.io/articles/la

  8. North Korea-linked hackers are hiding clues in public #Ethereum transactions to help malicious software find attacker-controlled servers. 6 npm packages were caught using the technique, putting software developers and their systems at risk.

    Listen/Read: hackread.com/dprk-hackers-ethe

    #Cybersecurity #NorthKorea #Malware #Crypto #Lazarus

  9. North Korea-linked hackers are hiding clues in public #Ethereum transactions to help malicious software find attacker-controlled servers. 6 npm packages were caught using the technique, putting software developers and their systems at risk.

    Listen/Read: hackread.com/dprk-hackers-ethe

    #Cybersecurity #NorthKorea #Malware #Crypto #Lazarus

  10. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  11. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  12. 📰 Lazarus Group Exploits Windows Zero-Day in Espionage Campaign

    Microsoft patches actively exploited Windows zero-day (CVE-2026-68820) used by Lazarus Group. The bug allows SYSTEM-level access and was used in the 'Operation Dream Job' campaign to deploy rootkits against the defense sector. #CVE202668820 #Lazarus ...

    🔗 cyber.netsecops.io/articles/la

  13. Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/laz

    Pulse ID: 6a7b1bec6c53b12a73b05e32
    Pulse Link: otx.alienvault.com/pulse/6a7b1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 12:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  14. Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/laz

    Pulse ID: 6a7b1bec6c53b12a73b05e32
    Pulse Link: otx.alienvault.com/pulse/6a7b1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 12:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  15. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  16. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  17. Grok does not have desktop app. So I produced one with Grok :)

    5.5MB binary!
    28MB RAM

    Thanks to and

  18. Grok does not have desktop app. So I produced one with Grok :)

    5.5MB binary!
    28MB RAM

    Thanks to #Lazarus and #FreePascal

  19. Small but super cool feature. RMB shoots raycast and list all the objects for easy selection.

    Idea stolen from Bryce 3D

  20. Small but super cool feature. RMB shoots raycast and list all the objects for easy selection.

    Idea stolen from Bryce 3D

    #Pascal #Lazarus #GameTool #3D #Modeling #RetroComputing #Bryce3D

  21. @slembcke @LordCaramac

    Forgive my #NecroReplying...

    I've been thinking about re-learning #Pascal and maybe picking up #Lazarus as well (#Delphi's #FOSS spiritual successor)... Maybe start a renaissance of #GUI development? 😂

  22. @slembcke @LordCaramac

    Forgive my #NecroReplying...

    I've been thinking about re-learning #Pascal and maybe picking up #Lazarus as well (#Delphi's #FOSS spiritual successor)... Maybe start a renaissance of #GUI development? 😂

  23. Terminado el #anime #lazarus

    Un anime cortito, y que me ha gustado. Se nota que es del creador de Cowboy Bebop, sobretodo con el prota, que me recordó al de Cowboy bebop cosa mala :NKO_hype: . Y lo de las palomas en todos lados... En fin, nostalgia.

    La historia de Lazarus me ha gustado, bastante actual a día de hoy, y el giro al final, me gustó más todavía.

    Los personajes, sin ser una locura, no están mal. Tb hay que tener en cuenta que es un anime bastante corto, 13 capitulos, asi que tp hay demasiado tiempo para indagar en ellos, siendo 5 protagonistas.

    Lo dicho, no me ha parecido una maravilla, pero está bien, solo son 13 capitulos, tiene una historia entretenida y los protas no están mal. A veces no hace falta mucho más para hacer un buen anime.

  24. Baugher reads Luke 16 with irritation: the rich man, condemned to hell, still tries ordering Lazarus about, as though nothing changed but his location. His heart stayed the same—still despising Moses. Today that charge gets redirected at those who suggest the rich should behave differently. The original target evades it entirely.

    #lutheranchurchmissourisynod #lutheran #bible #lazarus #serviceeconomy #gospel #gettysburgseminary

  25. 📣🚨 Developers watch out as North Korean #Lazarus hackers are now targeting npm developers with brandjacking packages that mimic trusted tools and, in reality, drop malware to steal credentials.

    Read: hackread.com/lazarus-group-npm

    #CyberSecurity #NorthKorea #Brandjacking #npm #Developers #Malware

  26. Цена одной опечатки: Как три неверные буквы сорвали киберограбление на миллиард долларов

    Взлом системы SWIFT часто кажется чем-то из области голливудской фантастики, но в 2016 году группировка Lazarus доказала обратное. В этой статье мы шаг за шагом разберем архитектуру одной из самых дерзких APT-атак в истории: на Центробанк Бангладеш. Вы узнаете, как хакеры использовали целевой фишинг для первичного проникновения, как обходили встроенную криптографию ПО Alliance Access в оперативной памяти и зачем им понадобилось модифицировать прошивку обычного матричного принтера. Это история о том, как тотальная экономия на сетевой инфраструктуре чуть не стоила суверенному государству миллиарда долларов.

    habr.com/ru/articles/1038600/

    #информационная_безопасность #lazarus #киберпреступность #swift #apt #малварь #хакеры #бангладеш #социальная_инженерия #уязвимости

  27. #Lazarus won Best Original Anime at the #CrunchyrollAnimeAwards.

    That's twice in a row that a #Toonami Original #anime has won this particular award. Not bad for a block that people still don't know is still running to this day.