Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
Ripple Shares North Korean Threat Intelligence to Combat Evolving Cyber Attacks
On May 5, 2026, Ripple announced it will share internal threat intelligence regarding North Korean hackers with Crypto ISAC, aimed at enhancing security across the cryptocurrency industry. This initiative follows a…
19 articles · Updated May 5, 2026 -
Bybit Sues North Korea Over $1.5 Billion Crypto Theft
Bybit has filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, accusing them of orchestrating a $1.5 billion hack in February 2025. The lawsuit, filed in the U.S. District…
23 articles · Updated August 8, 2026 -
China-aligned APT Groups Target Global Maritime and Tech Sectors Amid Geopolitical Tensions
ESET's latest APT Activity Report reveals that from October 2025 to March 2026, China-aligned threat actors engaged in extensive espionage campaigns, particularly in Venezuela and the Gulf region. Following U.S.…
6 articles · Updated May 28, 2026 -
Bitrefill Cyberattack Linked to North Korea's Lazarus Group Exposes Customer Data
Bitrefill, a crypto e-commerce platform, disclosed a cyberattack that began on March 1, 2026, attributed to North Korea's Lazarus Group. The breach started with a compromised employee laptop, allowing attackers to…
8 articles · Updated March 17, 2026 -
Operation Double Barrel: State-Sponsored Exploitation of Korean Financial Software
From 2025 to mid-2026, a state-sponsored threat group exploited vulnerabilities in Korean financial security software, utilizing watering hole attacks and spear phishing to deploy backdoors named Struggle and Brandoor.…
7 articles · Updated July 30, 2026 -
Critical RCE Vulnerability in GNU InetUtils telnetd Exposes Systems to Attacks
A critical vulnerability, CVE-2026-32746, has been discovered in the GNU InetUtils telnetd daemon, affecting all versions up to and including 2.7. This flaw allows unauthenticated remote attackers to execute arbitrary…
9 articles · Updated March 18, 2026 -
North Korea Adopts Modular Malware to Evade Detection and Takedowns
North Korea's cyber program has transitioned to a modular malware strategy, moving away from monolithic malware families to a more fragmented ecosystem. This change is a response to years of international sanctions, law…
3 articles · Updated April 6, 2026 -
Lazarus Group Faces Legal Battle Over $71 Million Crypto Theft
On May 6, 2026, a federal court in Manhattan began hearing claims over $71 million linked to North Korean cyberattacks. The claimants include families of victims from North Korean-attributed incidents and DeFi users…
9 articles · Updated May 11, 2026
Recent Intelligence Reports
- Lazarus used Windows zero — Feeds.4Sysops · August 12, 2026
- Lazarus hackers exploited Windows zero — Bleepingcomputer · August 12, 2026
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- Top 5 Cyber Threat Intelligence Services Benchmarked — Aimultiple · August 12, 2026
- Bybit Takes Unprecedented Legal Action After Crypto Hack — Cointribune · August 8, 2026
- State Hackers Made South Korea's Mandatory Banking Software Into Zero — Techtimes · July 30, 2026
- Kelp Dao Hacker Launders Nearly All 75700 Eth Through Thorchain — cointelegraph.com · June 1, 2026
- ESET APT Activity Report Q4 2025–Q1 2026 — Welivesecurity · May 28, 2026