ThreatCluster

New Lazarus and Kimsuky Infrastructure Exposed with Active Tools

First seen 18 Dec 2025, 21:53 UTC CybersecuritynewsGbhackers 40

Article Content

Browse articles
ThreatCluster

A joint investigation by Hunt.io and the Acronis Threat Research Unit has uncovered a new network associated with North Korean cyber actors Lazarus and Kimsuky. The research revealed active tool-staging servers, credential-theft environments, and tunneling nodes controlled by DPRK operators, indicating ongoing global cyber operations.