Researchers Uncovered New Lazarus and Kimsuky Infrastructure with Active Tools and Tunnelling Nodes
ID: 4fa9945d-6b9c-5cb4-8f3f-f7de68e8546a
STIX ID: report--4fa9945d-6b9c-5cb4-8f3f-f7de68e8546a
Feed Name: cybersecurityNews.com
Threat Score
Hunt.io and Acronis TRU uncovered a widespread North Korean (DPRK) operational infrastructure linking Lazarus and Kimsuky, revealing active tool-staging servers, credential-harvesters, FRP tunneling nodes, certificate reuse across clusters, and a new Linux Badcall backdoor variant with enhanced logging; exposed open directories and identified IP:port IOCs provide defenders actionable signals to detect and track these persistent, coordinated campaigns.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
