logo

Acronis TRU Alliance {Hunt.io}: Hunting DPRK threats - New Global Lazarus & Kimsuky campaigns

ID: 15611c1a-7102-5978-bd9b-cf76facd42c3

STIX ID: report--15611c1a-7102-5978-bd9b-cf76facd42c3

Feed Name: TRU Security by Acronis

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-07-24

...
...

This report documents a multi-hunt investigation linking DPRK threat actors (Lazarus, Kimsuky) through infrastructure artifacts: a new Linux Badcall backdoor variant, widespread FRP tunneling instances, exposed open directories hosting credential-harvesting and RAT tooling, and certificate-linked RDP/TLS clusters; it provides IOCs and defender hunting guidance to track these persistent, scriptable operational patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.