home.social

#lazarusgroup — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #lazarusgroup, aggregated by home.social.

fetched live
  1. crond, sshd, polkitd: la backdoor nordcoreana Ted infetta i demoni Linux nascosta dentro HAProxy

    Rapid7 documenta una campagna APT37 che troianizza HAProxy e i servizi di sistema Linux (crond, sshd, polkitd, agetty, atd) per spiare aziende sudcoreane di media e automotive. La backdoor Ted e il RAT companion CurlRAT restano invisibili per mesi grazie a timestamp falsificati e log ripuliti chirurgicamente.

    insicurezzadigitale.com/crond-

  2. crond, sshd, polkitd: la backdoor nordcoreana Ted infetta i demoni Linux nascosta dentro HAProxy

    Rapid7 documenta una campagna APT37 che troianizza HAProxy e i servizi di sistema Linux (crond, sshd, polkitd, agetty, atd) per spiare aziende sudcoreane di media e automotive. La backdoor Ted e il RAT companion CurlRAT restano invisibili per mesi grazie a timestamp falsificati e log ripuliti chirurgicamente.

    insicurezzadigitale.com/crond-

  3. crond, sshd, polkitd: la backdoor nordcoreana Ted infetta i demoni Linux nascosta dentro HAProxy

    Rapid7 documenta una campagna APT37 che troianizza HAProxy e i servizi di sistema Linux (crond, sshd, polkitd, agetty, atd) per spiare aziende sudcoreane di media e automotive. La backdoor Ted e il RAT companion CurlRAT restano invisibili per mesi grazie a timestamp falsificati e log ripuliti chirurgicamente.

    insicurezzadigitale.com/crond-

  4. crond, sshd, polkitd: la backdoor nordcoreana Ted infetta i demoni Linux nascosta dentro HAProxy

    Rapid7 documenta una campagna APT37 che troianizza HAProxy e i servizi di sistema Linux (crond, sshd, polkitd, agetty, atd) per spiare aziende sudcoreane di media e automotive. La backdoor Ted e il RAT companion CurlRAT restano invisibili per mesi grazie a timestamp falsificati e log ripuliti chirurgicamente.

    insicurezzadigitale.com/crond-

  5. crond, sshd, polkitd: la backdoor nordcoreana Ted infetta i demoni Linux nascosta dentro HAProxy

    Rapid7 documenta una campagna APT37 che troianizza HAProxy e i servizi di sistema Linux (crond, sshd, polkitd, agetty, atd) per spiare aziende sudcoreane di media e automotive. La backdoor Ted e il RAT companion CurlRAT restano invisibili per mesi grazie a timestamp falsificati e log ripuliti chirurgicamente.

    insicurezzadigitale.com/crond-

  6. 📰 North Korea's Lazarus Group Operations Decomposed into Six Clusters

    New research from Sekoia & Kudelski Security reveals North Korea's Lazarus Group is not a monolith, but six distinct clusters (Jade Sleet, Moonstone Sleet, etc.) focused on espionage & financial theft. #ThreatIntel #LazarusGroup #DPRK

    🔗 cyber.netsecops.io/articles/re

  7. هجوم Lazarus عبر عروض العمل الوهمية(هندسة اجتماعية) وثغرة Windows Zero-Day

    تفاصيل الهجوم شنّت مجموعة Lazarus المرتبطة بكوريا الشمالية حملة إلكترونية متطورة استهدفت فيها موظفين وشركات، خصوصًا في قطاعات الدفاع والطيران والفضاء. اعتمد الهجوم على ما يعرف بحملة Operation Dream Job، حيث ينتحل المهاجمون شخصية مسؤولي توظيف ويرسلون عروض عمل وهمية للضحايا بهدف […]

    cybercases8.wordpress.com/2026

  8. North Korea’s Lazarus Group Moved $30 Million Through Hyperliquid as US Entry Talks Accelerate — BigGo Finance

    Wallets tied to the North Korean state-sponsored Lazarus Group have moved more than $30 million in bitcoin through…
    #EuropeSays #Korea #KR #NorthKorea #Arkham #Bitwise #CFTC #Hyperliquid #HyperliquidLabs #Kraken #LazarusGroup #MikeSelig #OFAC #payward #TaylorMonahan #ZachXBT
    europesays.com/korea/139405/

  9. الاختراق المزدوج: قصة هجوم سلاسل التوريد المعقد على شركة 3CX

    البداية والهدف تُعد شركة 3CX واحدة من أشهر الشركات العالمية الموفرة لأنظمة الاتصالات والبدالات الرقمية (VoIP)، حيث يستخدم تطبيقها أكثر من 600,000 شركة و12 مليون مستخدم يومياً، مما جعل التطبيق هدفاً استراتيجياً لاختراق آلاف المؤسسات دفعة واحدة كيف سقط الفخ؟ في مارس 2023، حدث هجوم […]

    cybercases8.wordpress.com/2026

  10. الاختراق المزدوج: قصة هجوم سلاسل التوريد المعقد على شركة 3CX

    البداية والهدف تُعد شركة 3CX واحدة من أشهر الشركات العالمية الموفرة لأنظمة الاتصالات والبدالات الرقمية (VoIP)، حيث يستخدم تطبيقها أكثر من 600,000 شركة و12 مليون مستخدم يومياً، مما جعل التطبيق هدفاً استراتيجياً لاختراق آلاف المؤسسات دفعة واحدة كيف سقط الفخ؟ في مارس 2023، حدث هجوم […]

    cybercases8.wordpress.com/2026

  11. Σοκ: η «επίθεση» μπορεί να περάσει από συνέντευξη για δουλειά.

    Έρευνα που συνδέεται με τη Βόρεια Κορέα δείχνει πώς ύποπτοι προγραμματιστές απέκτησαν κανονική πρόσβαση σε εταιρικά συστήματα, χρησιμοποιώντας ψεύτικες ταυτότητες, VPN και AI.

    Αν μια εταιρεία προσλάβει το λάθος άτομο, μπορεί να το καταλάβει πολύ αργά.

    Δες ποια μικρά σημάδια τους πρόδωσαν.

    hacks.gr/proselavan-tychaia-vo

    #Cybersecurity #NorthKorea #LazarusGroup #InsiderThreat #IdentityFraud

  12. Lazarus Group exploits Windows zero-day to breach EU defense firms. Patch now!
    #ZeroDay #LazarusGroup #PatchNow

  13. 📢 Lazarus Group exploite un zero-day Windows (CVE-2026-68820) via de fausses offres d'emploi

    Cet article documente une nouvelle vague de la campagne Operation Dream Job, attribuée au groupe nord-coréen Lazarus, ciblant les secteurs de la défense, de l'aérospatiale et de l'aviation en Europe, Asie et Amérique du Sud.

    📖 cyberveille : cyberveille.ch/posts/2026-08-1
    🌐 source : blog.checkpoint.com/research/s
    🟢 vérification factuelle haute
    #LazarusGroup #ZeroDay #Cyberveille

  14. Lazarus Group is exploiting a Windows zero-day (CVE-2026-68820) to escalate to SYSTEM privileges and deploy backdoors. Targets include defense and aerospace firms in France, Germany, Brazil, and India, lured through fake LinkedIn job offers under Operation Dream Job.

    #LazarusGroup #ZeroDayExploit #WindowsSecurity #OperationDreamJob

    cyberworldops.eu/en/lazarus-ex

  15. Lazarus Group is exploiting a Windows zero-day (CVE-2026-68820) to escalate to SYSTEM privileges and deploy backdoors. Targets include defense and aerospace firms in France, Germany, Brazil, and India, lured through fake LinkedIn job offers under Operation Dream Job.

    #LazarusGroup #ZeroDayExploit #WindowsSecurity #OperationDreamJob

    cyberworldops.eu/en/lazarus-ex

  16. Lazarus Group has been exploiting a Windows zero-day as part of its ongoing Operation Dream Job campaign. The attackers pose as recruiters on professional platforms to target defense and aerospace organizations across France, Germany, Brazil, and India.

    #LazarusGroup #ZeroDay #OperationDreamJob #APTThreats

    cyberworldops.eu/en/lazarus-ex

  17. Lazarus Group has been exploiting a Windows zero-day as part of its ongoing Operation Dream Job campaign. The attackers pose as recruiters on professional platforms to target defense and aerospace organizations across France, Germany, Brazil, and India.

    #LazarusGroup #ZeroDay #OperationDreamJob #APTThreats

    cyberworldops.eu/en/lazarus-ex

  18. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  19. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  20. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  21. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  22. Anybody has Xctdoor/Xctloader samples that can share? I was trying to get the samples from this AhnLabs blog asec.ahnlab.com/en/94847/ alas, they are not in VirusTotal or Malware Bazaar...

    More than anything, I'm interested in samples employing these basic "obfuscation" techniques:

    #malware #xctdoor #xctloader #lazarus #lazarusgroup

  23. Bybit Sues North Korea in U.S. Over $1.5 Billion Hack — Pursues Legal Action to Trace Assets — BigGo Finance

    Bybit, a major cryptocurrency exchange, announced on August 7, 2026, that it has filed a civil lawsuit in…
    #EuropeSays #Korea #KR #NorthKorea #BenZhou #Bybit #Chainalysis #Ethereum(ETH) #FBI #LazarusGroup #ReconnaissanceGeneralBureau(RGB) #TraderTraitor #U.S.DistrictCourtfortheDistrictofColumbia
    europesays.com/korea/114145/

  24. Operation Double Barrel: quando lo spionaggio di stato nordcoreano condivide l’infrastruttura con il ransomware Gunra

    Un'advisory congiunta di NIS, NPA, KISA e FSI, basata su AhnLab ASEC, svela un anno e mezzo di attacchi state-sponsored contro la Corea del Sud tramite i backdoor Struggle/SIGNBT 3.0 e Brandoor/COPPERHEDGE. Sorprendente la sovrapposizione tecnica con episodi del ransomware Gunra: stesse vulnerabilità, stesse impronte SSH, stessa infrastruttura.

    insicurezzadigitale.com/operat

  25. Operation Double Barrel: quando lo spionaggio di stato nordcoreano condivide l’infrastruttura con il ransomware Gunra

    Un'advisory congiunta di NIS, NPA, KISA e FSI, basata su AhnLab ASEC, svela un anno e mezzo di attacchi state-sponsored contro la Corea del Sud tramite i backdoor Struggle/SIGNBT 3.0 e Brandoor/COPPERHEDGE. Sorprendente la sovrapposizione tecnica con episodi del ransomware Gunra: stesse vulnerabilità, stesse impronte SSH, stessa infrastruttura.

    insicurezzadigitale.com/operat

  26. Operation Double Barrel: quando lo spionaggio di stato nordcoreano condivide l’infrastruttura con il ransomware Gunra

    Un'advisory congiunta di NIS, NPA, KISA e FSI, basata su AhnLab ASEC, svela un anno e mezzo di attacchi state-sponsored contro la Corea del Sud tramite i backdoor Struggle/SIGNBT 3.0 e Brandoor/COPPERHEDGE. Sorprendente la sovrapposizione tecnica con episodi del ransomware Gunra: stesse vulnerabilità, stesse impronte SSH, stessa infrastruttura.

    insicurezzadigitale.com/operat

  27. Operation Double Barrel: quando lo spionaggio di stato nordcoreano condivide l’infrastruttura con il ransomware Gunra

    Un'advisory congiunta di NIS, NPA, KISA e FSI, basata su AhnLab ASEC, svela un anno e mezzo di attacchi state-sponsored contro la Corea del Sud tramite i backdoor Struggle/SIGNBT 3.0 e Brandoor/COPPERHEDGE. Sorprendente la sovrapposizione tecnica con episodi del ransomware Gunra: stesse vulnerabilità, stesse impronte SSH, stessa infrastruttura.

    insicurezzadigitale.com/operat

  28. Operation Double Barrel: quando lo spionaggio di stato nordcoreano condivide l’infrastruttura con il ransomware Gunra

    Un'advisory congiunta di NIS, NPA, KISA e FSI, basata su AhnLab ASEC, svela un anno e mezzo di attacchi state-sponsored contro la Corea del Sud tramite i backdoor Struggle/SIGNBT 3.0 e Brandoor/COPPERHEDGE. Sorprendente la sovrapposizione tecnica con episodi del ransomware Gunra: stesse vulnerabilità, stesse impronte SSH, stessa infrastruttura.

    insicurezzadigitale.com/operat

  29. Your quest, which you've already failed before accepting it, is to monitor threat intelligence feeds and endpoint security logs for indicators of Lazarus Group tool usage. The expansion pack is already installed. The final boss brought friends.

    Reward: You've received the Borrowed Doom Blade — pre-owned by a nation-state, gifted to strangers, definitely in your inventory now.

    #Ransomware #LazarusGroup #NorthKorea #CyberSecurity #APT #ThreatActorTeamUp (2/2)

  30. Your quest, which you've already failed before accepting it, is to monitor threat intelligence feeds and endpoint security logs for indicators of Lazarus Group tool usage. The expansion pack is already installed. The final boss brought friends.

    Reward: You've received the Borrowed Doom Blade — pre-owned by a nation-state, gifted to strangers, definitely in your inventory now.

    #Ransomware #LazarusGroup #NorthKorea #CyberSecurity #APT #ThreatActorTeamUp (2/2)

  31. Crypto Hacks Hit All-Time High as North Korea Drains Over $600M and AI Agents Become New Target

    Cryptocurrency projects recorded more verified hacks in the first six months of 2026 than in any previous full…
    #EuropeSays #Korea #KR #NorthKorea #AIagentexploit #Blockaid #Blockchainsecurity #cryptohack2026 #cryptocurrency #DeFisecurity #LazarusGroup
    europesays.com/korea/103009/

  32. Cynthia Lummis Says Crypto Act Will Strengthen Sanctions Compliance Against North Korea-Based Hackers and Other Bad Actors

    Sen. Cynthia Lummis (R-Wyo.) said on Sunday that the Clarity Act would close financial regulatory gaps that allowed North Korea’s Lazarus…
    #EuropeSays #Korea #KR #NorthKorea #ClarityAct #CynthiaLummis #LazarusGroup #suspicioustransactions #Treasury
    europesays.com/korea/100472/

  33. Cynthia Lummis Says Crypto Act Will Strengthen Sanctions Compliance Against North Korea-Based Hackers and Other Bad Actors

    Sen. Cynthia Lummis (R-Wyo.) said on Sunday that the Clarity Act would close financial regulatory gaps that allowed North Korea’s Lazarus…
    #EuropeSays #Korea #KR #NorthKorea #ClarityAct #CynthiaLummis #LazarusGroup #suspicioustransactions #Treasury
    europesays.com/korea/100430/

  34. Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup

    JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, furto di wallet crypto e monitoraggio della clipboard.

    insicurezzadigitale.com/lazaru

  35. Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup

    JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, furto di wallet crypto e monitoraggio della clipboard.

    insicurezzadigitale.com/lazaru

  36. Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup

    JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, furto di wallet crypto e monitoraggio della clipboard.

    insicurezzadigitale.com/lazaru

  37. Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup

    JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, furto di wallet crypto e monitoraggio della clipboard.

    insicurezzadigitale.com/lazaru

  38. Lazarus nasconde un RAT completo in sei pacchetti npm mascherati da polyfill Rollup

    JFrog scopre una nuova campagna di supply chain attribuita a Lazarus/Contagious Interview: pacchetti npm che imitano rollup-plugin-polyfill-node nascondono un impianto completo con accesso remoto, furto di wallet crypto e monitoraggio della clipboard.

    insicurezzadigitale.com/lazaru

  39. North Korea behind two-thirds of crypto theft in H1 2026, report says

    SEOUL, July 3 (UPI) — North Korean-linked hackers stole roughly $643 million in cryptocurrency during the first half…
    #EuropeSays #Korea #KR #NorthKorea #cryptocurrency #LazarusGroup #NorthKorean #TRMLabs
    europesays.com/korea/73341/

  40. 📰 Lazarus Group Unleashes 'RemotePE' Memory-Only RAT in Attacks on Financial and Crypto Firms

    🇰🇵 Lazarus Group deploys new 'RemotePE' memory-only RAT against financial & crypto firms. The fileless malware evades detection by never touching the disk, using a multi-stage infection chain. #LazarusGroup #Malware #ThreatIntel #RemotePE

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/la

  41. 📰 Lazarus Group Unleashes 'RemotePE' Memory-Only RAT in Attacks on Financial and Crypto Firms

    🇰🇵 Lazarus Group deploys new 'RemotePE' memory-only RAT against financial & crypto firms. The fileless malware evades detection by never touching the disk, using a multi-stage infection chain. #LazarusGroup #Malware #ThreatIntel #RemotePE

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/la

  42. Lazarus Group Deploys Memory-Only RAT in Financial Sector Attacks

    The notorious Lazarus Group has unleashed a sneaky new attack tool, a memory-only Remote Access Trojan (RAT), targeting the financial sector with cunning precision. This stealthy malware, known as RemotePE, is just the latest weapon in the group's arsenal, and it's being used to infiltrate and manipulate its victims.

    osintsights.com/lazarus-group-

    #LazarusGroup #RemoteAccessTrojan #Rat #FinancialSector #DecentralizedFinance

  43. North Korea-Linked Crypto Theft Hits $2B After 51% Surge in 2025

    The ‘Total Crypto Hack Value in 2026’ market currently shows a 70% YES chance for losses exceeding $1.2…
    #Conflict #Conflicts #War #cryptohacks #cryptosecurity #cryptotheft #LazarusGroup #northkorea #NorthKoreanhackers
    europesays.com/2995487/

  44. Banking Trojan Targets Crypto Firms with Sophisticated Attacks

    A new banking Trojan, dubbed TCLBanker, is wreaking havoc on crypto and finance platforms, allowing hackers to remotely control infected systems and steal sensitive info. This sophisticated attack, linked to North Korea's notorious Lazarus Group, has already led to the largest crypto platform hack of 2026.

    osintsights.com/banking-trojan

    #Tclbanker #BankingTrojan #LazarusGroup #NorthKorea #CryptoFirms

  45. La Corea del Nord ha rubato il 76% di tutte le criptovalute hackerate nel 2026: due attacchi, $577 milioni, e una macchina da guerra finanziata dal cyber

    Con solo due operazioni nel primo quadrimestre 2026, gli hacker nordcoreani hanno sottratto $577 milioni in criptovalute — il 76% di tutti i furti crypto globali. TRM Labs documenta come Pyongyang abbia trasformato il crimine DeFi in motore finanziario del proprio programma nucleare.

    insicurezzadigitale.com/la-cor

  46. La Corea del Nord ha rubato il 76% di tutte le criptovalute hackerate nel 2026: due attacchi, $577 milioni, e una macchina da guerra finanziata dal cyber

    Con solo due operazioni nel primo quadrimestre 2026, gli hacker nordcoreani hanno sottratto $577 milioni in criptovalute — il 76% di tutti i furti crypto globali. TRM Labs documenta come Pyongyang abbia trasformato il crimine DeFi in motore finanziario del proprio programma nucleare.

    insicurezzadigitale.com/la-cor

  47. La Corea del Nord ha rubato il 76% di tutte le criptovalute hackerate nel 2026: due attacchi, $577 milioni, e una macchina da guerra finanziata dal cyber

    Con solo due operazioni nel primo quadrimestre 2026, gli hacker nordcoreani hanno sottratto $577 milioni in criptovalute — il 76% di tutti i furti crypto globali. TRM Labs documenta come Pyongyang abbia trasformato il crimine DeFi in motore finanziario del proprio programma nucleare.

    insicurezzadigitale.com/la-cor

  48. La Corea del Nord ha rubato il 76% di tutte le criptovalute hackerate nel 2026: due attacchi, $577 milioni, e una macchina da guerra finanziata dal cyber

    Con solo due operazioni nel primo quadrimestre 2026, gli hacker nordcoreani hanno sottratto $577 milioni in criptovalute — il 76% di tutti i furti crypto globali. TRM Labs documenta come Pyongyang abbia trasformato il crimine DeFi in motore finanziario del proprio programma nucleare.

    insicurezzadigitale.com/la-cor

  49. La Corea del Nord ha rubato il 76% di tutte le criptovalute hackerate nel 2026: due attacchi, $577 milioni, e una macchina da guerra finanziata dal cyber

    Con solo due operazioni nel primo quadrimestre 2026, gli hacker nordcoreani hanno sottratto $577 milioni in criptovalute — il 76% di tutti i furti crypto globali. TRM Labs documenta come Pyongyang abbia trasformato il crimine DeFi in motore finanziario del proprio programma nucleare.

    insicurezzadigitale.com/la-cor