logo

Researchers Uncovered New Lazarus and Kimsuky Infrastructure with Active Tools and Tunnelling Nodes

ID: 4fa9945d-6b9c-5cb4-8f3f-f7de68e8546a

STIX ID: report--4fa9945d-6b9c-5cb4-8f3f-f7de68e8546a

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Hunt.io and Acronis TRU uncovered a widespread North Korean (DPRK) operational infrastructure linking Lazarus and Kimsuky, revealing active tool-staging servers, credential-harvesters, FRP tunneling nodes, certificate reuse across clusters, and a new Linux Badcall backdoor variant with enhanced logging; exposed open directories and identified IP:port IOCs provide defenders actionable signals to detect and track these persistent, coordinated campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.