logo

Inside DPRK Operations: New Lazarus and Kimsuky Infrastructure Uncovered Across Global Campaigns

ID: 4746439c-ad11-5e9e-b2fa-890560a30131

STIX ID: report--4746439c-ad11-5e9e-b2fa-890560a30131

Feed Name: Hunt.io Blog

Threat Score
90/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

This joint Hunt.io and Acronis TRU investigation maps DPRK-linked infrastructure across multiple hunts, linking Lazarus and Kimsuky activity through reused certificates, FRP tunneling, exposed open directories hosting credential-harvesters and RAT tooling, and a newly observed Linux variant of the Badcall backdoor; the report catalogs extensive IOCs and provides hunting and defender guidance to detect these recurring operational patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.