Related Threat Clusters
-
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
The North Korean hacking group Lazarus exploited a zero-day vulnerability (CVE-2026-68820) in the Windows Ancillary Function Driver for WinSock (afd.sys) to gain SYSTEM-level access to defense sector systems. This…
33 articles · Updated August 12, 2026 -
Lazarus Group Escalates Attacks with Fileless RemotePE Trojan Targeting Crypto and Banks
The Lazarus Group, a North Korea-linked cybercrime organization, has intensified its operations against financial and cryptocurrency sectors using a sophisticated fileless Remote Access Trojan (RAT) called RemotePE.…
12 articles · Updated May 25, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
Ripple Shares North Korean Threat Intelligence to Combat Evolving Cyber Attacks
On May 5, 2026, Ripple announced it will share internal threat intelligence regarding North Korean hackers with Crypto ISAC, aimed at enhancing security across the cryptocurrency industry. This initiative follows a…
19 articles · Updated May 5, 2026 -
Kelp DAO and Aave Resume Operations After $292 Million Exploit
On April 18, 2026, Kelp DAO suffered a significant cyberattack attributed to North Korea's Lazarus Group, resulting in the theft of approximately 116,500 rsETH tokens worth $292 million. The attackers exploited a…
9 articles · Updated May 14, 2026 -
North Korean Hackers Target Open Source Software Supply Chain via npm Packages
Amazon's threat intelligence has linked a series of compromises of popular npm packages—axios, debug, chalk, and typo-crypto—to a North Korean hacking group known as Sapphire Sleet. The group employed social engineering…
11 articles · Updated July 29, 2026 -
Kelp DAO Suffers $292 Million Loss in LayerZero Exploit Linked to Lazarus Group
Kelp DAO experienced a significant security breach on April 16, 2026, resulting in the loss of $292 million due to an exploit in the LayerZero ecosystem. Attackers, believed to be associated with North Korea's Lazarus…
35 articles · Updated May 5, 2026 -
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
The Kimsuky group, linked to North Korea, targeted South Korean groupware vendors from late 2025 to early 2026, deploying new malware variants BirdTroy and DriveTroy. These Linux backdoors utilized Google Drive for…
4 articles · Updated July 24, 2026 -
Coordinated Cyberattack Disrupts Water Utilities in Minnesota
A coordinated cyberattack affected water utilities in over 30 Minnesota communities on July 26 and 27, 2026. Key cities impacted include Plymouth, South St. Paul, Braham, and Maple Plain. The attack targeted…
321 articles · Updated July 27, 2026 -
Bybit Sues North Korea Over $1.5 Billion Crypto Theft
Bybit has filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, accusing them of orchestrating a $1.5 billion hack in February 2025. The lawsuit, filed in the U.S. District…
23 articles · Updated August 8, 2026
Recent Intelligence Reports
- August 2026 Patch Tuesday analysis — www.automox.com · August 13, 2026
- Lazarus Group Hacked Defense Workers With Windows Kernel Zero — Techtimes · August 13, 2026
- Significant Cyber Incidents — www.csis.org · August 13, 2026
- North Korea Hacked Defense Firms Four Times via Same Windows Driver; Patch Now — Techtimes · August 13, 2026
- Lazarus Group Exploited Windows Zero — Finance.Biggo · August 12, 2026
- CVE-2026-68820: Windows AFD.sys Zero-Day — Socprime · August 12, 2026
- Lazarus Used Post-Quantum Key Exchange to Deliver Zero — Infosecurity-Magazine · August 12, 2026
- Lazarus hackers pair fake job offers with Windows zero — Feeds2.Feedburner · August 12, 2026