home.social

#lazarus — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lazarus, aggregated by home.social.

fetched live
  1. Fałszywy startup-honeypot zatrudnił podejrzewanych operatorów Famous Chollima

    Badacze bezpieczeństwa z ANY.RUN stworzyli fikcyjny startup kryptowalutowy, zamieścili oferty pracy dla developerów i zatrudnili trzy osoby – ich zdaniem – z Korei Północnej. Udostępniane nowym pracownikom maszyny wirtualne rejestrowały ich aktywność. TLDR: Celem badaczy była Famous Chollima – jedna z wielu grup działających w ramach Lazarus. Ich cel jest...

    #WBiegu #Chollima #Koneypot #Lazarus #Startup

    sekurak.pl/falszywy-startup-ho

  2. CW: Linux-Kram, Fedora

    Eben mal #Lazarus Trunk mittels FpcUpDeluxe auf dem alten 2011-er #MacBook Pro mit #Fedora 44 installiert. 🤓

    Geht! … Wenn man noch so ein paar Pakete nach installiert (war ein bisschen suchen, weil die Pakete etwas anders aufgeteilt sind, als im Wiki beschriebenen Beispiel).

    Uuuund … die 4 GB RAM + 4 GB swap sind schon arg knapp - Firefox nebenbei sollte man besser schließen. 🙄 (man könnte aber natürlich auch mal sehen, wie man swap /dev/zram0 vergrößern kann 😉)

    PS: warum macht man sowas? Weil‘s geht! Forschertrieb.

  3. Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed

    Part 2: Hiring North Korean IT workers in a fake DeFi startup shows how the country’s infamous “Famous Chollima” cyber-espionage operation works.

    Pulse ID: 6a8693c10ec0d620c77b5808
    Pulse Link: otx.alienvault.com/pulse/6a869
    Pulse Author: Tr1sa111
    Created: 2026-08-20 05:42:25

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #Espionage #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #bot #cyberespionage #Tr1sa111

  4. От одного npm‑пакета к кластеру Contagious Interview: практическое расследование supply chain‑кампании

    В прошлой статье я рассказывал о случайно попавшем ко мне образце ChainVeil - вредоносном ПО из источника, который на тот момент не был зафиксирован в публичных исследованиях. На этот раз первым сигналом стал мой собственный supply chain‑мониторинг. Он сообщил о новом npm‑пакете plugin-react-vite . На первый взгляд это выглядело как очередной тайпсквоттинг - ничего особенно необычного. Но я решил пойти дальше: сначала проверить метаданные пакета, затем код, затем инфраструктуру, а уже после этого попытаться понять, кто стоит за образцом и связан ли он с чем‑то уже известным. В результате расследование ушло далеко за пределы одного package.json : от подозрительной зависимости я пришел к второму этапу размером около 30 тысяч строк, а затем - к нескольким месяцам активности, связанным пакетам, нескольким npm‑аккаунтам и уже известному кластеру. Именно этот путь я и хочу разобрать. Погрузится в расследование

    habr.com/ru/articles/1072054/

    #investigation #threat_intelligence #lazarus #apt #реверсинжиниринг #reverseengineering #расследование #аналитика #npm

  5. North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/laz

    Pulse ID: 6a82e8d11134c2cd6f7e0e58
    Pulse Link: otx.alienvault.com/pulse/6a82e
    Pulse Author: CyberHunter_NL
    Created: 2026-08-17 10:56:17

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #CyberSecurity #Government #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL

  6. 🚨 🥷 #Lazarus zero-day targets defense firms

    North Korean hackers exploited Windows to gain privileged access.
    🔗 read more: www.bleepingcomputer...

    #ransomNews #cybersecurity


    Lazarus hackers exploited Wind...

  7. Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access

    Pulse ID: 6a7e137d417182865191ce16
    Pulse Link: otx.alienvault.com/pulse/6a7e1
    Pulse Author: cryptocti
    Created: 2026-08-13 18:57:01

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #InfoSec #Lazarus #OTX #OpenThreatExchange #Windows #ZeroDay #bot #cryptocti

  8. State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit

    North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.

    Pulse ID: 6a7d8b5671a34dd89301bbbe
    Pulse Link: otx.alienvault.com/pulse/6a7d8
    Pulse Author: AlienVault
    Created: 2026-08-13 09:16:05

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault

  9. Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7cc1f91810a474e1284a56
    Pulse Link: otx.alienvault.com/pulse/6a7cc
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 18:56:57

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL

  10. Ein #Sicherheitsforscher hat wohl fast zwei Jahre lang unbemerkt die Systeme nordkoreanischer Hackergruppen wie #Lazarus mitgelesen.

    Zentrale Erkenntnis: Die Cyberkriminellen attackieren oft nicht die Zielfirmen direkt, sondern kompromittieren IT-#Dienstleister, die in die Systeme mehrerer Kunden eingebunden sind.

    Eine einzige erfolgreiche Übernahme öffnet damit oft #Root-Zugänge zu Servern und Cloud-Umgebungen zahlreicher Unternehmen auf einen Schlag:

    wired.com/story/a-security-pro #cybersecurity

  11. North Korea-linked hackers are hiding clues in public #Ethereum transactions to help malicious software find attacker-controlled servers. 6 npm packages were caught using the technique, putting software developers and their systems at risk.

    Listen/Read: hackread.com/dprk-hackers-ethe

    #Cybersecurity #NorthKorea #Malware #Crypto #Lazarus

  12. Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit

    Indicators extracted from public reporting. Source: research.checkpoint.com/2026/s

    Pulse ID: 6a7beecb020ccbfd7b706fad
    Pulse Link: otx.alienvault.com/pulse/6a7be
    Pulse Author: CyberHunter_NL
    Created: 2026-08-12 03:55:55

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL

  13. Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers

    Indicators extracted from public reporting. Source: any.run/cybersecurity-blog/laz

    Pulse ID: 6a7b1bec6c53b12a73b05e32
    Pulse Link: otx.alienvault.com/pulse/6a7b1
    Pulse Author: CyberHunter_NL
    Created: 2026-08-11 12:56:12

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL

  14. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  15. Grok does not have desktop app. So I produced one with Grok :)

    5.5MB binary!
    28MB RAM

    Thanks to and

  16. Small but super cool feature. RMB shoots raycast and list all the objects for easy selection.

    Idea stolen from Bryce 3D

  17. @slembcke @LordCaramac

    Forgive my #NecroReplying...

    I've been thinking about re-learning #Pascal and maybe picking up #Lazarus as well (#Delphi's #FOSS spiritual successor)... Maybe start a renaissance of #GUI development? 😂