lazarusholic
@lazarusholic.bsky.social
๐ค 128
๐ฅ 15
๐ 1210
a big fan of lazarus.
https://lazarus.day
"From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet" published by Microsoft. #Mastra, #NPM, #SapphireSleet, #DPRK, #CTI
https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/
4 days ago
0
0
0
"Mastra npm Scope Takeover: 143 Packages Drop a RAT" published by SafeDep. #Mastra, #NPM, #DPRK, #CTI
https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/
4 days ago
0
0
0
"์ ์ ์ด๋ ฅ์์ฒ๋ผ ๋ณด์ด์ง๋ง ์คํ ์๊ฐ ๊ฐ์ผ ์์" published by Ahnlab. #LNK, #Xctdoor, #DPRK, #CTI
https://asec.ahnlab.com/ko/94163/
7 days ago
0
0
0
"๊ฐ์ธ์ ๋ณด ๋์์์ธ ์ค ์์๋ ๋ฐ๋ก๊ฐ๊ธฐ ํ์ผ์ ์ ์ฒด๋?" published by Ahnlab. #Kimsuky, #LNK, #DPRK, #CTI
https://asec.ahnlab.com/ko/94162/
7 days ago
0
0
0
"Chai.js ํ๋ฌ๊ทธ์ธ์ผ๋ก ์์ฅํ ๋ถํ๋ฐ npm ์ ์ฑ ํจํค์ง 'chai-as-init' ๋ถ์" published by ESTSecurity. #ContagiousInterview, #NPM, #DPRK, #CTI
https://blog.alyac.co.kr/5766
7 days ago
0
0
0
"Humanity Protocol" published by Rekt. #HumanityProto, #DPRK, #CTI
https://rekt.news/humanity-protocol-rekt
8 days ago
0
0
0
"$H Incident Summary" published by Humanity. #HumanityProto, #DPRK, #CTI
https://www.humanity.org/hincidentupdate
8 days ago
0
0
0
"Exposing DPRK Employment Fraud Operations" published by NISOS. #ITWorker, #PiKVM, #DPRK, #CTI
https://nisos.com/research/dprk-employment-fraud-operation/
8 days ago
0
0
0
"$H Incident: Tooling Linked to North Korean Actors" published by Humanity. #HumanityProto, #DPRK, #CTI
https://x.com/Humanityprot/status/2065480523057647652
8 days ago
0
0
0
"Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2" published by Genians. #APT37, #LNK, #NarwhalRAT, #DPRK, #CTI
https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat
10 days ago
0
0
0
"MS ์ฌ์นญ ํผ์ฑ๊ณผ Dead-drop C2 ๊ธฐ๋ฐ APT37 NarwhalRAT ๋ถ์" published by Genians. #APT37, #LNK, #NarwhalRAT, #DPRK, #CTI
https://www.genians.co.kr/blog/threat_intelligence/narwhalrat
10 days ago
0
0
0
"The North Korean IT worker threat: A modern insider risk" published by Corelight. #Deepfake, #ITWorker, #DPRK, #CTI
https://corelight.com/blog/north-korean-it-worker-insider-threat
10 days ago
0
0
0
"astro.config.mjs Supply Chain Attack via Blockchain C2" published by SafeDep. #PolinRider, #DPRK, #CTI
https://safedep.io/astro-config-blockchain-c2-supply-chain
10 days ago
0
0
0
"Hunting North Korea's job adverts on Google Docs" published by Kmsec. #FamousChollima, #DPRK, #CTI
https://kmsec.uk/blog/dprk-google-docs/
13 days ago
0
2
0
"CrowdStrike 2026 Report: China Fuels Attacks on Tech" published by CrowdStrike. #FamousChollima, #LabyrinthChollima, #StardustChollima, #Trend, #DPRK, #CTI
https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-technology-threat-landscape-report/
14 days ago
0
1
0
"Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency" published by Proofpoint. #ContagiousInterview, #UNK_DeadDrop, #DPRK, #CTI
https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal
15 days ago
0
1
0
"Lazarus Group's Latest: Brandjacking Campaign on npm" published by Sonatype. #NPM, #Lazarus, #DPRK, #CTI
https://www.sonatype.com/blog/lazarus-groups-latest-brandjacking-campaign-on-npm
20 days ago
0
0
0
"Lazarus Group: The Hackers With a National Budget" published by PureFi. #Lazarus, #DPRK, #CTI
https://medium.com/purefi/lazarus-group-the-hackers-with-a-national-budget-41f1878fc131
20 days ago
0
0
0
"APT-C-26๏ผLazarus๏ผ็ป็ปๅฉ็จCVE-2025-55182ไธCopperhedge็ปไปถ็ๆปๅป่กๅจๅๆ" published by Qihoo360. #APT-C-26, #CVE-2025-55182, #Copperhedge, #DPRK, #CTI
https://mp.weixin.qq.com/s/3kwDMAXviaE1TUDnkYlqrg
20 days ago
0
0
0
"์๋ฒฝ์ ์จ ์ํธํ ์๋ Endpoint(Midnight) ๋์ฌ์จ์ด ๋ถ์" published by Ahnlab. #Endpoint, #Midnight, #Ransomware, #Suspicious, #DPRK, #CTI
https://asec.ahnlab.com/ko/93931/
22 days ago
0
0
0
"Tracking North Korea Nation-State APT Infrastructure: Kimsuky" published by Idanmalihi. #Kimsuky, #DPRK, #CTI
https://idanmalihi.com/tracking-north-korea-nation-state-apt-infrastructure-kimsuky/
22 days ago
0
0
0
"Famous Chollima Targets PHP Developers Through Compromised Packagist Package" published by Socket. #ContagiousInterview, #FamousChollima, #DPRK, #CTI
https://socket.dev/blog/famous-chollima-targets-php-developers-through-compromised-packagist-package
22 days ago
0
0
0
"Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign" published by Levelblue. #SapphireSleet, #macOS, #DPRK, #CTI
https://www.levelblue.com/blogs/spiderlabs-blog/sapphire-sleet-targets-macos-in-multi-stage-intrusion-campaign
24 days ago
0
0
1
"Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace" published by SafeDep. #FamousChollima, #HuggingFace, #NPM, #DPRK, #CTI
https://safedep.io/microsoftsystem64-binary-payload-analysis/
26 days ago
0
0
0
"ESET APT Activity Report Q4 2025โQ1 2026" published by ESET. #Andariel, #DangerousPassword, #DeceptiveDevelopment, #DreamJob, #Rook, #ScarCruft, #DPRK, #CTI
https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2025-q1-2026.pdf
27 days ago
0
0
0
"Threat Actor Targets Crypto Organizations" published by Wiz. #JINX-0164, #Suspicious, #macOS, #DPRK, #CTI
https://www.wiz.io/blog/threat-actors-target-crypto-orgs
27 days ago
0
1
0
"Kimsuky์ ๊ณ ๋ํ๋ ๊ณต๊ฒฉ ๊ธฐ๋ฒ ๋ถ์: JSONPing, Webex ์ฌ์นญ, ๊ทธ๋ฆฌ๊ณ ์๋ก์ด HttpSpy ๋ณ์ข " published by ENKI. #HttpSpy, #JSONPing, #Kimsuky, #DPRK, #CTI
https://www.enki.co.kr/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant
27 days ago
0
0
0
"Kimsuky's Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant" published by ENKI. #HttpSpy, #JSONPing, #Kimsuky, #DPRK, #CTI
https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant
27 days ago
0
0
0
"KimjongRAT ๋ณ์ข : ์ ๋ณด ํ์ทจ์์ ์๊ฒฉ ์ ๊ทผ ํ๋ณด๋ก์ ํ์ฅ" published by Hauri. #KimjongRAT, #DPRK, #CTI
https://hauri.co.kr/security/security_view.html?intSeq=88&page=1&keyfield=&key=
27 days ago
0
0
0
"More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild" published by Proofpoint. #CVE-2026-21510, #LNK, #Phishing, #TA406, #DPRK, #CTI
https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild
28 days ago
0
0
0
"โ๋ณด์ ๋ฉ์ผโ๋ ์์ฌ ๊ธ๋ฌผ! ์นด๋์ฌ ์ฌ์นญ ์ ์ฑ ํ์ผ ์ ํฌ ์ค" published by Ahnlab. #Kimsuky, #LNK, #MeshAgent, #DPRK, #CTI
https://asec.ahnlab.com/ko/93854/
28 days ago
0
0
0
"DPRK Captive Portal Infrastructure Found in Testing" published by NKInternet. #OpSec, #DPRK, #CTI
https://nkinternet.com/2026/05/26/dprk-captive-portal-infrastructure-found-in-testing/
28 days ago
0
0
0
"I was likely targeted by DPRK in a sophisticated developer malware campaign" published by Denv. #ContagiousInterview, #VSCode, #DPRK, #CTI
https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-a-sophisticated-developer-malware-campaign/
28 days ago
0
1
0
"2026๋ 4์ APT ๊ณต๊ฒฉ ๋ํฅ ๋ณด๊ณ ์(๊ตญ๋ด)" published by Ahnlab. #LNK, #Phishing, #DPRK, #CTI
https://asec.ahnlab.com/ko/93830/
29 days ago
0
0
0
"A Fake Coding Interview Is an Execution Request: Developer Safety Checklist" published by RedAsgard. #GitHub, #Lazarus, #NPM, #VSCode, #DPRK, #CTI
https://redasgard.com/blog/fake-coding-interview-developer-safety-checklist
30 days ago
0
1
0
"RemotePE: The Lazarus RAT that lives in memory" published by Foxit. #Lazarus, #RemotePE, #DPRK, #CTI
https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/
30 days ago
0
0
0
"OFAC Sanctions Tracker: How Sanctions Impact Crypto Crime" published by Chainalysis. #ITWorker, #Sanctions, #DPRK, #CTI
https://www.chainalysis.com/blog/ofac-sanctions/
about 1 month ago
0
0
0
"Hunting Lazarus Part IX: The Google Mirror" published by RedAsgard. #BeaverTail, #OtterCookie, #DPRK, #CTI
https://redasgard.com/blog/hunting-lazarus-part9-google-mirror
about 1 month ago
0
0
0
"Cross-Platform NPM Stealer" published by Dshield. #NPM, #OtterCookie, #DPRK, #CTI
https://dshield.org/diary/CrossPlatform+NPM+Stealer/33006/
about 1 month ago
0
0
0
"Analyzing Void Dokkaebiโs Cython-Compiled InvisibleFerret Malware" published by TrendMicro. #InvisibleFerret, #VoidDokkaebi, #DPRK, #CTI
https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html
about 1 month ago
0
0
0
"Interview with the Chollima VIII" published by Bitso. #ITWorker, #DPRK, #CTI
https://quetzal.bitso.com/p/interview-with-the-chollima-viii
about 1 month ago
0
0
0
"North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT" published by OxSecurity. #NPM, #DPRK, #CTI
https://www.ox.security/blog/north-korean-npm-infostealer-rat/
about 1 month ago
0
0
1
"Cyber Threat Intelligence Report 2026" published by Bridewell. #Trend, #Collaboration, #NPM, #DPRK, #CTI
https://www.bridewell.com/insights/white-papers/detail/cyber-threat-intelligence-report-2026
about 1 month ago
0
1
1
"LayerZero Labs KelpDAO Incident Report" published by LayerZero.
#KelpDAO
,
#TraderTraitor
,
#DPRK
,
#CTI
https://layerzero.network/publications/kelpdao-incident-report.pdf
about 1 month ago
0
0
0
"DPRK Activity Evolution Through Campaign Linkage" published by Krypt3ia. #Cryptocurrency, #ITWorker, #SupplyChain, #DPRK, #CTI
https://krypt3ia.wordpress.com/2026/05/19/threat-intelligence-report-dprk-activity-evolution-through-campaign-linkage/
about 1 month ago
0
0
0
"Axios attacker strikes again! Three NPM packages have been hiding in plain sight for two months" published by OSM. #Axios, #NPM, #UNC1069, #DPRK, #CTI
https://opensourcemalware.com/blog/axios-attacker-additional-npm-packages
about 1 month ago
0
0
0
"Deep Dive into Active Github Network Running Contagious Interview" published by meowmfer. #ContagiousInterview, #BeaverTail, #OmniStealer, #DPRK, #CTI
https://archive.md/JMkiH
about 1 month ago
0
0
0
"Hunting Lazarus Part VIII: OtterCookie" published by RedAsgard. #Lazarus, #OtterCookie, #DPRK, #CTI
https://redasgard.com/blog/hunting-lazarus-part8-ottercookie
about 1 month ago
0
0
0
"1๋ถ๊ธฐ DPRK Operation Kimsuky ๋ถ์" published by Logpresso. #GitHub, #Kimsuky, #LNK, #DPRK, #CTI
https://logpresso.com/ko/blog/2026-05-15-1Q-Kimsuky-report
about 1 month ago
0
0
1
"How malware abuses npm lifecycle scripts and VS Code tasks" published by OSM. #Axios, #NPM, #TasksJacker, #DPRK, #CTI
https://opensourcemalware.com/blog/malware-abuses-vscode-lifecycle-scripts
about 1 month ago
0
0
0
Load more
feeds!
log in