logo

Operation Phantom Circuit: North Korea’s Global Data Exfiltration Campaign

ID: 0403243e-6168-5c61-9017-45175397fba0

STIX ID: report--0403243e-6168-5c61-9017-45175397fba0

Feed Name: SecurityScorecard Blog

Threat Score
90/100

Date Published: 2025-04-17

Date Updated: 2026-04-29

...
...

**Executive Summary:** STRIKE attributes a sophisticated, large-scale supply-chain campaign called “Phantom Circuit” to North Korea’s Lazarus Group, reporting that attackers embedded malware into trusted development tools to compromise ~1,500 developer systems across three waves, operated a modern React/Node.js C2 platform, used VPNs and Oculus proxies to obfuscate origin, and exfiltrated credentials and other sensitive data to Dropbox.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.