New Lazarus and Kimsuky Infrastructure Exposed with Active Tools
Article Content
Browse articles
A joint investigation by Hunt.io and the Acronis Threat Research Unit has uncovered a new network associated with North Korean cyber actors Lazarus and Kimsuky. The research revealed active tool-staging servers, credential-theft environments, and tunneling nodes controlled by DPRK operators, indicating ongoing global cyber operations.
Ask AI about this cluster
Answers cite the sources they use
Updated 213d ago How this analysis works
More articles in this cluster (2)
Following this threat?
Track Kimsuky in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
2026 AV-Comparatives EPR Test Results Released AV-Comparatives published the results of its 2026 Endpoint Prevention and Response (EPR) Test, evaluating 14 enterprise security products against 50 multi-stage attack scenarios. The test, which ran from May to August 2026, incorporated AI-assisted techniques and followed the MITRE ATT&CK framework. Eleven products…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…