#lazarus — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #lazarus, aggregated by home.social.
-
Fałszywy startup-honeypot zatrudnił podejrzewanych operatorów Famous Chollima
Badacze bezpieczeństwa z ANY.RUN stworzyli fikcyjny startup kryptowalutowy, zamieścili oferty pracy dla developerów i zatrudnili trzy osoby – ich zdaniem – z Korei Północnej. Udostępniane nowym pracownikom maszyny wirtualne rejestrowały ich aktywność. TLDR: Celem badaczy była Famous Chollima – jedna z wielu grup działających w ramach Lazarus. Ich cel jest...
#WBiegu #Chollima #Koneypot #Lazarus #Startup
https://sekurak.pl/falszywy-startup-honeypot-zatrudnil-podejrzewanych-operatorow-famous-chollima/
-
CW: Linux-Kram, Fedora
Eben mal #Lazarus Trunk mittels FpcUpDeluxe auf dem alten 2011-er #MacBook Pro mit #Fedora 44 installiert. 🤓
Geht! … Wenn man noch so ein paar Pakete nach installiert (war ein bisschen suchen, weil die Pakete etwas anders aufgeteilt sind, als im Wiki beschriebenen Beispiel).
Uuuund … die 4 GB RAM + 4 GB swap sind schon arg knapp - Firefox nebenbei sollte man besser schließen. 🙄 (man könnte aber natürlich auch mal sehen, wie man swap /dev/zram0 vergrößern kann 😉)
PS: warum macht man sowas? Weil‘s geht! Forschertrieb.
-
Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed
Part 2: Hiring North Korean IT workers in a fake DeFi startup shows how the country’s infamous “Famous Chollima” cyber-espionage operation works.
Pulse ID: 6a8693c10ec0d620c77b5808
Pulse Link: https://otx.alienvault.com/pulse/6a8693c10ec0d620c77b5808
Pulse Author: Tr1sa111
Created: 2026-08-20 05:42:25Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Espionage #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #bot #cyberespionage #Tr1sa111
-
От одного npm‑пакета к кластеру Contagious Interview: практическое расследование supply chain‑кампании
В прошлой статье я рассказывал о случайно попавшем ко мне образце ChainVeil - вредоносном ПО из источника, который на тот момент не был зафиксирован в публичных исследованиях. На этот раз первым сигналом стал мой собственный supply chain‑мониторинг. Он сообщил о новом npm‑пакете plugin-react-vite . На первый взгляд это выглядело как очередной тайпсквоттинг - ничего особенно необычного. Но я решил пойти дальше: сначала проверить метаданные пакета, затем код, затем инфраструктуру, а уже после этого попытаться понять, кто стоит за образцом и связан ли он с чем‑то уже известным. В результате расследование ушло далеко за пределы одного package.json : от подозрительной зависимости я пришел к второму этапу размером около 30 тысяч строк, а затем - к нескольким месяцам активности, связанным пакетам, нескольким npm‑аккаунтам и уже известному кластеру. Именно этот путь я и хочу разобрать. Погрузится в расследование
https://habr.com/ru/articles/1072054/
#investigation #threat_intelligence #lazarus #apt #реверсинжиниринг #reverseengineering #расследование #аналитика #npm
-
North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring
Indicators extracted from public reporting. Source: https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/
Pulse ID: 6a82e8d11134c2cd6f7e0e58
Pulse Link: https://otx.alienvault.com/pulse/6a82e8d11134c2cd6f7e0e58
Pulse Author: CyberHunter_NL
Created: 2026-08-17 10:56:17Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ANYRUN #CyberSecurity #Government #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RAT #RCE #bot #CyberHunter_NL
-
🚨 🥷 #Lazarus zero-day targets defense firms
North Korean hackers exploited Windows to gain privileged access.
🔗 read more: www.bleepingcomputer...
#ransomNews #cybersecurity
Lazarus hackers exploited Wind... -
Windows AFD.sys Zero-Day Exploited by Lazarus Hackers to Gain SYSTEM Access
Pulse ID: 6a7e137d417182865191ce16
Pulse Link: https://otx.alienvault.com/pulse/6a7e137d417182865191ce16
Pulse Author: cryptocti
Created: 2026-08-13 18:57:01Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #InfoSec #Lazarus #OTX #OpenThreatExchange #Windows #ZeroDay #bot #cryptocti
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
North Korea-affiliated Lazarus group has resurfaced with Operation Dream Job, leveraging a previously unknown Windows vulnerability (CVE-2026-68820) to target defense, aerospace, and aviation organizations. The campaign uses fake job offers from recruiters via platforms like LinkedIn to deliver malicious payloads through two infection chains: DLL sideloading with MISTPEN downloader and a trojanized PDF viewer called SecurityPDF that deploys the Troy backdoor. The zero-day exploit enables privilege escalation to deploy a rootkit that evades EDR detection. Attackers utilize compromised legitimate websites and Roundcube webmail servers running RelayShell as command and control infrastructure, masking malicious traffic as normal activity. Victims are concentrated in Europe, Asia, and South America, with particular focus on France, Germany, Brazil, and India. Microsoft patched the vulnerability following disclosure.
Pulse ID: 6a7d8b5671a34dd89301bbbe
Pulse Link: https://otx.alienvault.com/pulse/6a7d8b5671a34dd89301bbbe
Pulse Author: AlienVault
Created: 2026-08-13 09:16:05Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#Asia #BackDoor #Brazil #CyberSecurity #EDR #Europe #France #Germany #India #InfoSec #Korea #Lazarus #LinkedIn #Microsoft #NorthKorea #OTX #OpenThreatExchange #PDF #RAT #Rootkit #SideLoading #SouthAmerica #Trojan #Vulnerability #Webmail #Windows #ZeroDay #bot #AlienVault
-
Lazarus Post-Quantum Key Exchange Used to Deliver Windows Zero-Day - https://www.redpacketsecurity.com/lazarus-used-post-quantum-key-exchange-to-deliver-zero-day/
-
State Sponsored Hackers Use Fake Job Offers to Deliver New Zero Day Exploit
#Lazarus #CVE_2026_68820
https://blog.checkpoint.com/research/state-sponsored-hackers-use-fake-job-offers-to-deliver-new-zero-day-exploit/ -
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7cc1f91810a474e1284a56
Pulse Link: https://otx.alienvault.com/pulse/6a7cc1f91810a474e1284a56
Pulse Author: CyberHunter_NL
Created: 2026-08-12 18:56:57Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#BackDoor #CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Windows #ZeroDay #bot #CyberHunter_NL
-
Ein #Sicherheitsforscher hat wohl fast zwei Jahre lang unbemerkt die Systeme nordkoreanischer Hackergruppen wie #Lazarus mitgelesen.
Zentrale Erkenntnis: Die Cyberkriminellen attackieren oft nicht die Zielfirmen direkt, sondern kompromittieren IT-#Dienstleister, die in die Systeme mehrerer Kunden eingebunden sind.
Eine einzige erfolgreiche Übernahme öffnet damit oft #Root-Zugänge zu Servern und Cloud-Umgebungen zahlreicher Unternehmen auf einen Schlag:
https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/ #cybersecurity
-
North Korea-linked hackers are hiding clues in public #Ethereum transactions to help malicious software find attacker-controlled servers. 6 npm packages were caught using the technique, putting software developers and their systems at risk.
Listen/Read: https://hackread.com/dprk-hackers-ethereum-malicious-npm-packages/
-
Lazarus Hackers Actively Exploiting Windows AFD.sys Zero-Day to Deploy FudModule Rootkit
Indicators extracted from public reporting. Source: https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Pulse ID: 6a7beecb020ccbfd7b706fad
Pulse Link: https://otx.alienvault.com/pulse/6a7beecb020ccbfd7b706fad
Pulse Author: CyberHunter_NL
Created: 2026-08-12 03:55:55Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #HTTP #HTTPS #InfoSec #Lazarus #OTX #OpenThreatExchange #RCE #Rootkit #Windows #ZeroDay #bot #CyberHunter_NL
-
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Indicators extracted from public reporting. Source: https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two/
Pulse ID: 6a7b1bec6c53b12a73b05e32
Pulse Link: https://otx.alienvault.com/pulse/6a7b1bec6c53b12a73b05e32
Pulse Author: CyberHunter_NL
Created: 2026-08-11 12:56:12Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#ANYRUN #CyberSecurity #HTTP #HTTPS #InfoSec #Korea #Lazarus #NorthKorea #OTX #OpenThreatExchange #RCE #bot #CyberHunter_NL
-
Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog https://asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...
More than anything, I'm interested in samples employing these basic "obfuscation" techniques:
-
Grok does not have desktop app. So I produced one with Grok :)
5.5MB binary!
28MB RAMThanks to #Lazarus and #FreePascal
-
-
-
I will finally have a vertex paint tool that just works ;)
-
-
Shinichiro Watanabe didn't just luck out. "I had to fight for everything," says the director of "Cowboy Bebop" and "Lazarus," looking back on his 30-year career in a book from Kadokawa. https://www.japantimes.co.jp/culture/2026/07/16/books/shinichiro-watanabe-book/?utm_medium=Social&utm_source=mastodon #culture #books #shinichirowatanabe #cowboybebop #samuraichamploo #lazarus #anime