New Lazarus and Kimsuky Infrastructure Exposed with Active Tools
First seen 18 Dec 2025, 21:53 UTC
•
•40
Export
Article Content
Browse articles
A joint investigation by Hunt.io and the Acronis Threat Research Unit has uncovered a new network associated with North Korean cyber actors Lazarus and Kimsuky. The research revealed active tool-staging servers, credential-theft environments, and tunneling nodes controlled by DPRK operators, indicating ongoing global cyber operations.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
More articles in this cluster
Continue Reading
Kimsuky Expands AI Capabilities for Cyberattacks
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
FamousSparrow APT Expands Targeting to Azerbaijani Energy Sector
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
Kimsuky Targets South Korea with Advanced Malware and Social Engineering Tactics