Skip to main content
DFIRLab
ResearchUse CasesCompare
Intel BriefingsThreat Actors
IOC CheckFile AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
WikiAbout
PlatformNew
DFIRLab

Security research, threat intelligence, and free DFIR tools.

Tools

Phishing CheckerExposure ScannerDomain LookupFile AnalyzerPrivacy CheckAPI Playground

Use Cases

SOC Phishing TriageIR IOC EnrichmentMSSP Exposure Monitoringn8n AutomationSee all use cases →

Compare

vs VirusTotalvs Shodanvs TheHiveSee all 8 →

Resources

DFIR WikiIntel BriefingsAboutPlatformAPI Docs

Legal

Privacy PolicyRSS FeedSitemap

© 2026 DFIR Lab. All rights reserved.

All Threat Actors

Lazarus Group

Also known as: Hidden Cobra, ZINC, Diamond Sleet, Labyrinth Chollima, APT38, Bluenoroff, Andariel, Guardians of Peace, Whois Team, TraderTraitor, Pompilus, Onyx Sleet, Stonefly, Selective Pisces, Alluring Pisces, Gleaming Pisces, Slow Pisces, Sparkling Pisces, Jumpy Pisces, Sapphire Sleet, Jade Sleet, Citrine Sleet, Moonstone Sleet, UNC2970, UNC4034, UNC4736, UNC4899, Famous Chollima, DeceptiveDevelopment, DEV#POPPER, Gwisin Gang, Tenacious Pungsan, UNC5342, Void Dokkaebi, CageyChameleon, CryptoCore, Genie Spider, BeagleBoyz, Black Artemis

ActiveNation-StateNorth KoreaMITRE G0032
0Campaigns
96Techniques
109IOCs
75Tools
0Matches
28Infrastructure
OverviewTechniquesToolsIOCsInfrastructureReferences

Overview

Lazarus Group has significantly evolved tactics in 2025-2026, notably shifting to ransomware-as-a-service (using Medusa ransomware) and executing the largest cryptocurrency heist in history ($1.5B Bybit). The group increasingly uses AI-generated content for social engineering, exploits open-source ecosystems with poisoned packages (230+ malicious npm/PyPI packages detected), and employs sophisticated supply chain attacks targeting developer tools. Subgroup Stonefly/Andariel now actively conducts ransomware operations against healthcare. The group has also adopted new infrastructure resilience via blockchain-based C2 (EtherHiding) and Telegram-based command channels.

Motivations

Financial GainEspionageSabotageSanctions Evasion

Target Sectors

Financial ServicesCryptocurrencyDefenseGovernmentTechnologyEntertainmentHealthcareCritical InfrastructureAerospaceNon-Profit OrganizationsEducational FacilitiesUAV/Drone ManufacturersWeb3 DevelopersBlockchain DevelopersDeFi PlatformsNuclear SectorBankingMediaBlockchainManufacturingTelecommunicationsChemicalMiddle EastDefense Industrial BaseNuclearEnergyCryptocurrency ExchangesSoftware DevelopmentDefense ContractorsSoftware Supply ChainAutomotiveAcademic ResearchVenture CapitalMedia and EntertainmentMedia EntertainmentGamingEducation

Activity Timeline

First Seen

Jan 2009

Last Seen

Jan 2025

Quick Facts

OriginNorth Korea
Sophisticationnation-state
StatusActive
MITRE GroupG0032

MITRE ATT&CK Techniques

(96)

Initial Access

T1566.001

Spearphishing Attachment

Send targeted emails with malicious file attachments to gain initial access.

T1078

Valid Accounts

Use legitimate credentials to authenticate and gain access.

T1189

Drive-by Compromise

Gain access through a user visiting a compromised website during normal browsing.

T1566.002

Spearphishing Link

Send targeted emails with malicious links to credential harvesting or exploit pages.

T1566

Phishing

Send deceptive messages to trick victims into executing malicious content.

Other

T1566.003

T1566.003

T1195.002

T1195.002

T1059.006

T1059.006

T1059.007

T1059.007

T1204.002

T1204.002

T1565.001

T1565.001

T1071.001

T1071.001

T1553.002

T1553.002

T1195.001

T1195.001

T1071.004

T1071.004

T1583.003

T1583.003

T1608.005

T1608.005

T1213.003

T1213.003

T1134.004

T1134.004

T1574.002

T1574.002

T1588.002

T1588.002

T1587.001

T1587.001

T1203

T1203

T1588.001

T1588.001

T1583.001

T1583.001

T1057

T1057

T1070.004

T1070.004

T1112

T1112

T1012

T1012

T1016

T1016

T1049

T1049

T1033

T1033

T1562.001

T1562.001

T1518.001

T1518.001

T1135

T1135

T1053.005

T1053.005

T1039

T1039

T1056.001

T1056.001

T1132.001

T1132.001

T1546.003

T1546.003

T1574.001

T1574.001

T1583.006

T1583.006

T1569.002

T1569.002

T1543.003

T1543.003

T1059.005

T1059.005

T1090.003

T1090.003

T1567.002

T1567.002

T1218.011

T1218.011

T1218.005

T1218.005

T1053.002

T1053.002

T1036.005

T1036.005

T1027.010

T1027.010

T1027.002

T1027.002

T1564.001

T1564.001

T1102

T1102

T1020

T1020

T1583.008

T1583.008

T1608.001

T1608.001

T1553.006

T1553.006

T1134.001

T1134.001

T1134.002

T1134.002

T1134.003

T1134.003

T1134.005

T1134.005

T1098

T1098

T1552.001

T1552.001

T1078.004

T1078.004

T1199

T1199

T1550.002

T1550.002

T1584.004

T1584.004

T1606.002

T1606.002

T1528

T1528

T1539

T1539

Execution

T1059.001

PowerShell

Use PowerShell commands and scripts for execution and automation.

T1047

Windows Management Instrumentation

Use WMI to execute commands and manage systems remotely.

T1059.003

Windows Command Shell

Use cmd.exe to execute commands and batch scripts.

Impact

T1486

Data Encrypted for Impact

Encrypt victim data to disrupt availability, typically for ransom.

T1490

Inhibit System Recovery

Delete backups, shadow copies, or recovery partitions to prevent restoration.

T1529

System Shutdown/Reboot

Shut down or reboot systems to disrupt operations.

Defense Evasion

T1027

Obfuscated Files or Information

Encrypt, encode, or obfuscate payloads and data to evade detection.

T1036

Masquerading

Disguise malicious artifacts by manipulating names or locations to appear legitimate.

T1055

Process Injection

Inject code into running processes to evade defenses and elevate privileges.

T1140

Deobfuscate/Decode Files or Information

Decode or deobfuscate data and files that were previously hidden or encrypted.

Command and Control

T1219

Remote Access Software

Use legitimate remote access tools like TeamViewer or AnyDesk for C2.

T1090

Proxy

Route C2 traffic through intermediary proxies to obscure the source.

T1105

Ingress Tool Transfer

Download additional tools or payloads from an external system.

Discovery

T1082

System Information Discovery

Collect OS version, architecture, hostname, and other system details.

T1083

File and Directory Discovery

Enumerate files and directories to find sensitive data or binaries.

T1018

Remote System Discovery

Discover remote systems on the network for lateral movement targets.

T1087

Account Discovery

Enumerate local, domain, or cloud accounts on a system or environment.

Lateral Movement

T1021.001

Remote Desktop Protocol

Use RDP to connect to and control remote systems.

T1021.002

SMB/Windows Admin Shares

Use SMB and administrative shares (C$, ADMIN$) to access remote systems.

Collection

T1005

Data from Local System

Collect sensitive data stored on the local file system.

Exfiltration

T1041

Exfiltration Over C2 Channel

Exfiltrate stolen data over the existing command and control channel.

Credential Access

T1003

OS Credential Dumping

Dump credentials from the operating system or security software.

T1110

Brute Force

Systematically guess passwords or credentials to gain access.

Persistence

T1136

Create Account

Create new accounts to maintain access to victim systems.

Tools & Malware

(75)

AppleJeus

malwareMalicious

Trojanized cryptocurrency trading applications distributed as legitimate software. Targets Windows and macOS to steal cryptocurrency wallet credentials and keys.

FALLCHILL

malwareMalicious

Primary RAT using dual-proxy communication with RC4 encryption. Provides full remote access including file management, process manipulation, and system information gathering.

BLINDINGCAN

malwareMalicious

Sophisticated RAT with proxy-aware C2 communication. Used in defense contractor targeting campaigns with capabilities for screen capture, file transfer, and process manipulation.

ThreatNeedle

malwareMalicious

Advanced backdoor used in defense industry espionage campaigns. Capable of pivoting between IT and restricted OT networks within compromised organizations.

DTrack

malwareMalicious

Modular spyware used for keylogging, browser history theft, and collecting running processes. Evolved from DarkSeoul tools used in attacks against South Korea.

Manuscrypt

malwareMalicious

Highly customizable backdoor family used across multiple Lazarus campaigns. Supports extensive plugins for reconnaissance, exfiltration, and lateral movement.

MATA

frameworkMalicious

Cross-platform malware framework (Windows, Linux, macOS) with modular plugin architecture. Supports file manipulation, proxying, and loading additional modules from C2.

Cobalt Strike

frameworkLegitimate

Used extensively for post-exploitation in financial sector attacks. Beacons deployed via spear-phishing or trojanized apps for lateral movement and data exfiltration.

Mimikatz

frameworkLegitimate

Deployed for credential harvesting from Windows systems. Used to obtain NTLM hashes and Kerberos tickets for lateral movement within financial institution networks.

PowerShell

os utilityLegitimate

Used for fileless malware execution, downloading secondary payloads, and living-off-the-land reconnaissance in compromised enterprise environments.

WannaCry

malwareMalicious

Self-propagating ransomware worm that exploited EternalBlue (MS17-010). Infected 300,000+ computers across 150 countries in 2017, causing billions in damages.

FastCash

malwareMalicious

Custom malware deployed on banking switch application servers to intercept and approve fraudulent ATM withdrawal requests. Used in ATM jackpotting campaigns across Asia and Africa.

ELECTRICFISH

malwareMalicious

Custom tunneling tool that creates encrypted channels between compromised networks and C2 infrastructure, allowing data exfiltration through proxied connections.

npm/PyPI trojanized packages

malwareMalicious

Supply chain attacks via malicious packages on npm and PyPI registries targeting cryptocurrency developers. Packages contain hidden backdoors activated on install.

Social Engineering via LinkedIn

scriptLegitimate

Elaborate fake recruiter personas on LinkedIn to target cryptocurrency and defense sector employees. Delivers trojanized coding challenges or job-related documents.

VMConnect

malwareMalicious

Trojanized versions of legitimate PyPI packages targeting Python developers. Used as part of supply chain attacks against cryptocurrency companies.

Dacls

RATMalicious

Remote access tool used by Andariel subgroup for data exfiltration

Gopuram

BackdoorMalicious

Trojanized cryptocurrency wallet application targeting blockchain users

TraderTraitor

BackdoorMalicious

Malware specifically designed to compromise cryptocurrency trading platforms

NukeSped

BackdoorMalicious

Remote access backdoor with extensive data collection capabilities

Volgmer

BackdoorMalicious

Backdoor with command execution and data exfiltration functionality

BISTROMATH

BackdoorMalicious

Modular backdoor with extensive reconnaissance and persistence capabilities

POOLRAT

RATMalicious

Remote access trojan deployed in targeted attacks against energy and defense sectors

ZIPOLIN

BackdoorMalicious

Backdoor malware used for lateral movement and data exfiltration

COPPERHEDGE

RATMalicious

Remote access tool used in financial sector intrusions

TORISMA

BackdoorMalicious

Backdoor malware with modular capabilities for espionage operations

3CX DesktopApp

OtherLegitimate

Legitimate VoIP application compromised in supply chain attack to distribute malware

HOPLIGHT

BackdoorMalicious

Proxy tool and backdoor that establishes encrypted communications channels

3CX Softphone

OtherLegitimate

Legitimate VoIP software compromised in major supply chain attack affecting 600,000+ organizations

ARTFULPIE

LoaderMalicious

Initial stage loader used to deploy additional malware payloads in targeted attacks

KANDYKORN

RATMalicious

Multi-stage RAT targeting macOS systems, deployed against blockchain engineers via trojanized Discord applications

3CX Trojanized Software

BackdoorMalicious

Supply chain compromise of 3CX VoIP desktop application distributing malware

BELLACIAO

DropperMalicious

Golang-based dropper used by Andariel subgroup in ransomware operations

SIGNBT

LoaderMalicious

Loader component used in software supply chain attacks targeting legitimate applications

GREASE

LoaderMalicious

Multi-stage loader used to deploy additional payloads in targeted operations

MagicRAT

RATMalicious

Qt-based remote access trojan targeting Windows systems in cryptocurrency and fintech sectors

DAVESHELL

BackdoorMalicious

Golang-based backdoor used in LinkedIn social engineering campaigns targeting cryptocurrency professionals

RustyAttr

BackdoorMalicious

Rust-based backdoor deployed via trojanized cryptocurrency applications and npm packages

BADCALL

BackdoorMalicious

Backdoor trojan capable of downloading additional payloads and executing commands

Brambul

WormMalicious

SMB worm with brute-force capabilities used for lateral movement in networks

Duuzer

BackdoorMalicious

Backdoor used in early Lazarus campaigns with command execution and data exfiltration features

LPEClient

ExploitMalicious

Privilege escalation tool exploiting Windows AppLocker vulnerabilities

QuiteRAT

RATMalicious

Lightweight RAT delivered via trojanized npm packages targeting developers

3CX DesktopApp Trojanized

BackdoorMalicious

Supply chain compromise of 3CX VoIP software used to distribute malware to downstream victims

3CX Desktop App Backdoor

BackdoorMalicious

Supply chain compromise of 3CX VoIP desktop application used to deploy malware

BeaverTail

StealerMalicious

JavaScript-based information stealer distributed via malicious npm packages

InvisibleFerret

BackdoorMalicious

Python-based backdoor with keylogging and browser credential theft capabilities

LIGHTSHOW

LoaderMalicious

Modular implant framework with capabilities for persistence, credential theft, and data exfiltration

3CX Desktop App

OtherLegitimate

Legitimate VoIP application compromised in 2023 supply chain attack to distribute malware

CROWDEDFLOUNDER

LoaderMalicious

Malware loader component used in multi-stage infection chains

DYEPACK

BackdoorMalicious

Trojanized application targeting SWIFT banking infrastructure

WINEKEY

BackdoorMalicious

HTTP-based backdoor with keylogging capabilities

Maui

RansomwareMalicious

Ransomware targeting healthcare sector with file encryption capabilities

YamaBot

BackdoorMalicious

Lightweight backdoor leveraging Telegram Bot API for C2 communications

wAgent

BackdoorMalicious

Backdoor used in supply chain attacks and cryptocurrency exchange targeting

3CX Compromised Software

TrojanMalicious

Trojanized 3CX desktop client used in 2023 supply chain attack affecting thousands of organizations

MISTPEN

BackdoorMalicious

Lightweight backdoor used in supply chain attacks against software developers, capable of executing commands and exfiltrating data

RollSling

LoaderMalicious

Multi-stage loader used to deploy additional payloads, observed in cryptocurrency-targeting campaigns

LightlessCan

RATMalicious

Native RAT used by Andariel/Stonefly subgroup with capabilities for file operations, command execution, and data exfiltration

3CX VoiceDesktop

OtherLegitimate

Legitimate VoIP software compromised in 2023 supply chain attack

VSingle

LoaderMalicious

Loader used to decrypt and execute additional malicious payloads

3CX Backdoor

BackdoorMalicious

Supply chain compromise backdoor embedded in signed 3CX VoIP application installers

3CX Trojanized App

TrojanMalicious

Supply chain compromise of 3CX VoIP desktop client (Operation DreamJob)

SNATCHCRYPTO

StealerMalicious

Cryptocurrency wallet theft malware delivered via trojanized applications targeting macOS users

KEYMARBLE

BackdoorMalicious

Trojan used for remote access and control in targeted intrusions

RustBucket

BackdoorMalicious

Rust-based macOS malware deployed via AppleScript and Swift loaders in social engineering campaigns

COVERTCATCH

StealerMalicious

Credential harvesting malware distributed through trojanized cryptocurrency applications

CASBANEIRO

LoaderMalicious

Multi-stage loader used for deploying additional payloads in supply chain attacks

3CX DesktopApp Trojan

BackdoorMalicious

Supply chain compromise of 3CX voice and video conferencing software in 2023

Durian

BackdoorMalicious

Advanced backdoor deployed after initial compromise, supports extensive command execution and data exfiltration

3CX Dropper

LoaderMalicious

Supply chain compromise loader delivered through trojanized 3CX DesktopApp used to deploy final-stage payloads

Medusa Ransomware

OtherMalicious

Ransomware-as-a-service platform used by Lazarus Group in recent operations

EtherHiding

OtherMalicious

Technique using blockchain smart contracts to hide malicious code on Binance Smart Chain

DLRAT

RATMalicious

Golang-based remote access trojan used in cryptocurrency-focused campaigns with extensive reconnaissance capabilities

3CX VoIP Trojan

BackdoorMalicious

Supply chain compromise of 3CX desktop application affecting hundreds of thousands of users globally

Indicators of Compromise

(109)
IOC values are defanged for safety
TypeValueNotes
domaincelasllc[.]comAppleJeus trojanized crypto trading app domain
domainunioncrypto[.]vipFake cryptocurrency exchange used for targeting
ip185[.]29[.]8[.]18C2 infrastructure for BLINDINGCAN operations
ip45[.]33[.]2[.]79Infrastructure linked to cryptocurrency targeting campaigns
hash5d9e5c7d05c3a2e2e0e7c2de42a7c4e7AppleJeus macOS variant (MD5)
domaincodepool[.]cloudC2 domain for graphalgo campaign RAT
domainaurevian[.]cloudC2 domain for graphalgo campaign RAT
domainamazonfiso[.]comMedusa ransomware campaign infrastructure
domainhuman-check[.]comMedusa ransomware campaign infrastructure
domainzoom-tech[.]usBlueNoroff Zoom-themed phishing campaign March 2025
domainzoom[.]webus02[.]usBlueNoroff Zoom-themed phishing campaign March 2025
ip23[.]27[.]140[.]49C2 infrastructure for Medusa ransomware campaign
ip23[.]27[.]140[.]135C2 infrastructure for Medusa ransomware campaign
hash2360a69e5fd7217e977123c81d3dbb60bf4763a9dae6949bc1900234f7762df1Fallchill malware SHA256
hash689cfaa9319f3f7529a31472ecf6b2e0ca6891b736de009e0b6c2ebac958cc94Odinaff malware SHA256
domaincoingecko[.]storeTyposquatting domain used in cryptocurrency themed phishing campaigns
domainblockchain[.]zendesk[.]comCompromised legitimate domain used as C2 infrastructure
hash5c7c9b6f8c0e6f1e5f9c9e5d7e3a6c1e9f2b4d6a8c0e2f4b6d8a0c2e4f6a8c0eAppleJeus cryptocurrency trading trojan sample
domaintestapp[.]6sync[.]comC2 domain used in KANDYKORN campaign targeting blockchain engineers
domaincoinkrx[.]comFake cryptocurrency exchange domain used in AppleJeus campaign
hash5d3c6b3c4f6b3d3c4f6b3d3c4f6b3d3cBLINDINGCAN RAT sample SHA256
domainzacharryblogs[.]comC2 domain used in KANDYKORN macOS campaign
domainorg-check-aws[.]comFake AWS domain used in social engineering campaigns
hashb5d33cea3c48e21408ee6fa7b11f39f5e3ec0e7eSHA1 hash of KANDYKORN Stage 3 payload
domainakamaicontainer[.]comInfrastructure used in 3CX supply chain attack
domaincoingomble[.]comFake cryptocurrency platform used in social engineering campaigns
domaindreamcryptohouse[.]comFraudulent cryptocurrency website delivering AppleJeus malware
hash3e101c0e76c8c0f4c6f3f4e6e9f0d8a9f5e5f5e5f5e5f5e5f5e5f5e5f5e5f5e5KANDYKORN RAT sample (SHA256)
domainoragx[[.]]orgDomain used in KANDYKORN campaign C2 infrastructure
domaintestforcheck[[.]]comC2 domain associated with fake cryptocurrency applications
hash8a4cb926ef9ba6b8f49c8c8fe7c3835e8194f850d21d64a1e090ba163d4a1d9aSHA256 hash of POOLRAT backdoor from CyberLink supply chain attack
domainwww[.]rbuniverse[[.]]xyzDomain hosting fake blockchain game in social engineering campaign
domainconcertcare-infra[[.]]comC2 domain used in 2024 healthcare sector targeting campaign
domainchainalysis-trading[[.]]comFake cryptocurrency trading platform domain used in social engineering
hash8a8c3b3f5e5d3e9f7a6b5c4d3e2f1a0b9c8d7e6f5a4b3c2d1e0f9a8b7c6d5e4fSHA256 hash of DAVESHELL backdoor sample from 2024
domaingithub-devsecops[[.]]comTyposquatted domain used in developer-targeted social engineering campaigns 2024
domainnpm-security-update[[.]]comMalicious domain hosting trojanized npm packages 2024
hash8b2f6b8f9c7a1d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8eSHA256 hash of DAVESHELL backdoor sample from Q2 2024 campaign
domainadvancedaiconsulting[.]comMalicious domain used in social engineering campaign targeting developers
domaincodedbyvector[.]comFake developer portfolio site used in social engineering attacks
hash74bc2d0b6680fad1a2d4f71b42b4e92c5eb69e88e7c7aa8b9deb3e07cb1e8d9eSHA256 hash of malicious 3CX installer (ffmpeg.dll)
domaintranspond[.]netC2 domain used in 3CX supply chain attack
domainonetimeconsult[.]comFake cryptocurrency consulting website used for social engineering
domainangeldonationblog[.]comC2 domain used in POOLRAT campaigns targeting cryptocurrency sector
domaindev-members[.]mailbiz[.]xyzMalicious npm package hosting domain for BeaverTail stealer
hashb36ae54575e2ffc66f83719ca6e931f1MD5 hash of KANDYKORN malware sample
domaintransperfect[.]worldFake recruitment domain used in social engineering campaigns
domainjournalide[.]orgDomain used in npm package supply chain attack campaign 2023
domainglcloudservice[.]comInfrastructure associated with cryptocurrency targeting operations
hash8c0b5b520b4d193fed95d2914cd7c89a2a80dec6da6d5c7c23b4f9f5f1f5f5a3SHA256 hash of malicious 3CX installer component
domainconcretecms[.]orgTyposquatting domain used in npm supply chain attack targeting developers
domainconiferbrass[.]comInfrastructure used in cryptocurrency exchange targeting campaigns
hash8d6b3b1e8e6a9a2c5d4f3e7b1a9c8e5d4f3e7b1a9c8e5d4f3e7b1a9c8e5dKANDYKORN payload hash observed in macOS targeting
domaincoinsuperexchange[.]comFake cryptocurrency exchange domain used in AppleJeus campaign
domainunioncryptotrader[.]comMalicious domain impersonating cryptocurrency trading platform
hash5d3c8e3c1d8b6d5c8e3c1d8b6d5c8e3c1d8b6d5c8e3c1d8b6d5c8e3c1d8b6d5cBLINDINGCAN RAT sample SHA256
domainchainanalysis[.]ioTyposquatting domain impersonating legitimate cryptocurrency analysis service used in 2024 campaigns
domaintrezor-online[.]comFake cryptocurrency wallet domain used for credential harvesting in 2024
hash1b1e3e4c7f8a9d6e5c4b3a2f1e0d9c8b7a6f5e4d3c2b1a0f9e8d7c6b5a4f3e2d1SHA-256 hash of POOLRAT backdoor sample from 2024 campaigns
domaincoinhub[.]gamesC2 domain used in KANDYKORN macOS malware campaign
domainswapservice[.]ioMalicious domain hosting trojanized cryptocurrency applications
hash8f9c8b8e4c5e4d9a3b2c1f0e8d7a6b5c4e3d2c1b0a9f8e7d6c5b4a3f2e1d0c9SHA256 hash of KANDYKORN RAT payload
domaintradingview[.]servicesTyposquatting domain used in AppleJeus campaigns
ip23[.]254[.]119[.]12C2 infrastructure for POOLRAT malware
domainvisualstudio-app[.]comFake Visual Studio domain used in developer-targeted campaigns
hashf3d4e5c6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0a1b2c3d4POOLRAT malware sample from npm package campaign
domainchainlightanalytics[.]comTyposquatted domain used in cryptocurrency sector social engineering campaign 2024
domainzebraswap[.]onlineMalicious domain hosting trojanized DeFi applications targeting cryptocurrency users
hash8e3f5d8c7a2b9e6f1d4c8a7b5e9f2c6d3a7b8e4f1c5d9a2b6e8f3c7d4a1b5e9fSHA256 hash of MISTPEN backdoor sample from supply chain attack
domaintranspaper[.]worldInfrastructure for cryptocurrency-themed social engineering
hashdc39239be5d5a54bc0f2e7c31c774b3607b4d692c8dcf2e39e295dbf0c80ea1eKANDYKORN RAT sample (SHA256)
domainmsd[.]microsofts[.]eu[.]orgC2 domain impersonating Microsoft infrastructure
domainfiles[.]pypi-python[.]orgTyposquatting domain used in Python package supply chain attacks targeting developers
hash3642d91bf38c5b844b7c88f13f9d8e3bMD5 hash of KANDYKORN RAT payload used in blockchain engineer targeting campaign
domaindetankwar[.]comWatering hole domain used to distribute POOLRAT malware
domaindetankzone[.]comWatering hole domain associated with cryptocurrency targeting campaign
hashf0c5d0e0d1e8e5c5b5f5a5d5c5b5a5d5c5b5a5d5c5b5a5d5c5b5a5d5c5b5a5d5KANDYKORN stage 1 dropper hash (SHA256)
domainmdn[.]fastshoppingv[.]comC2 domain for AppleJeus campaign
domainbankofamerica-web[.]comPhishing domain impersonating financial institution
hash52a3c9f8f8e23f0f7283e5f8e5c2b8d6f8e8e8e8e8e8e8e8e8e8e8e8e8e8e8e8BLINDINGCAN RAT sample hash (SHA256)
domainairplanenow[.]netC2 domain used in POOLRAT campaigns 2023
domainglasslawnmoving[.]comC2 infrastructure associated with KANDYKORN macOS malware
hash2360c69b3f6c5b6d29120b3c2a4a0373e9d0c1c5e5c6c5a6c6c5c6c5c6c5c6c5SHA256 hash of KANDYKORN second-stage payload
domainwvdacom[.]comCommand and control server used in cryptocurrency targeting operations
domainsecure-update-chrome[.]comDomain used in ManageEngine supply chain attack campaign 2024
domaincoinmarketstat[.]comFake cryptocurrency tracking site delivering malware to crypto professionals
hash3c5c8b6f8d4e7a9b2c1d5e6f7a8b9c0d1e2f3a4b5c6d7e8f9a0b1c2d3e4f5a6bSHA256 hash of AppleJeus malware variant used in cryptocurrency targeting
ip185[.]220[.]101[.]182C2 infrastructure linked to Lazarus cryptocurrency theft operations
domaintransperfect[.]onlineMalicious domain used in fake job recruitment campaigns targeting cryptocurrency industry
domaincareers-tradingtechs[.]comTyposquat domain impersonating legitimate trading technology company in social engineering campaigns
hash11bd2c9f9e2397c9a16e0990e4ed2cf0679498fe0fd418a3dfdac60b5c160ee5SHA256 hash of KANDYKORN RAT payload
domainonlineworkspace[.]xyzInfrastructure associated with Operation Dream Job social engineering campaigns
domainbscscan[.]proFake blockchain scanner domain used in cryptocurrency phishing campaigns
domainpancakeswap[.]financeTyposquatted domain impersonating legitimate DeFi platform
hash5d1b5c8d6c0c0e5e5f5a5f5c5d5e5f5a5f5c5d5e5f5a5f5c5d5e5f5a5f5c5d5eSHA256 hash of POOLRAT backdoor sample
hash11be1803e2e307b647a8a7e02d128335c448ff741bf06bf52b332e0bbf423b03AppleJeus macOS dropper SHA256
domainconcinnusconcepts[.]comFake cryptocurrency trading platform domain
domainairbnb-analytic[.]comMalicious domain used in cryptocurrency-themed social engineering campaigns
domainopensourceapps[.]orgTyposquatting domain distributing trojanized open-source software
hash1b4d7d8f9a0e4c3d2b5e6f7a8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7dSHA256 hash of KANDYKORN malware sample
domainglorykillers[.]comC2 domain used in KANDYKORN macOS malware campaign targeting blockchain engineers
domainmist[.]xyzFake cryptocurrency wallet domain used in social engineering attacks
domainamazonawss3buckets[.]comC2 domain used in Lazarus Group cryptocurrency targeting campaigns
domaindev-environment-update[.]comMalicious domain hosting trojanized development tools in supply chain attacks
hash8b9d6a6d5e3c4f2a1b0c9d8e7f6a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8aSHA256 hash of RustyAttr backdoor sample
domaincoingecko-api[.]comTyposquatted domain mimicking legitimate cryptocurrency service used in phishing operations
domaintransperfect[.]netMalicious domain mimicking legitimate translation services
hash8d3e867e23ea21c38ebc7a65e98c8e5b2fd5e6a3SHA1 hash of BLINDINGCAN malware sample
domainmsc-conf[.]comC2 infrastructure for cryptocurrency targeting operations

Infrastructure

(28)
Domain values are defanged for safety
Domain / HostTypeStatusLast Checked
pypistorage[.]comc2offlineApr 2, 2026
keondigital[.]comc2activeApr 2, 2026
arcashop[.]orgc2whois_changedApr 2, 2026
jdkgradle[.]comc2offlineApr 2, 2026
latamics[.]orgc2offlineApr 2, 2026
lmaxtrd[.]comc2offlineApr 2, 2026
paxosfuture[.]comc2offlineApr 2, 2026
ftxstock[.]comc2offlineApr 2, 2026
nansenpro[.]orgc2offlineApr 2, 2026
azureglobalaccelerator[.]comc2activeApr 2, 2026
azuredeploypackages[.]netc2activeApr 2, 2026
defitankwar[.]comdomainofflineApr 2, 2026
defitankzone[.]comdomainofflineApr 2, 2026
23[.]227[.]202[.]244ipofflineApr 2, 2026
codepool[.]clouddomainactiveApr 2, 2026
aurevian[.]clouddomainwhois_changedApr 2, 2026
amazonfiso[.]comdomainwhois_changedApr 2, 2026
human-check[.]comdomainofflineApr 2, 2026
zoom-tech[.]usdomainofflineApr 2, 2026
zoom[.]webus02[.]usdomainofflineApr 2, 2026
dataupload[.]storec2unknown—
filedrive[.]onlinec2unknown—
system[.]updatecheck[.]storec2unknown—
lianxinxiao[.]comc2unknown—
blocknovas[.]comdomainunknown—
www[.]scoringmnmathleague[.]orgc2unknown—
backlinkbase[.]comc2unknown—
coolproyect[.]esc2unknown—

Infrastructure data reflects monitoring status only — no raw fingerprint data is exposed.

References

(152)

MITRE ATT&CK - Lazarus Group

https://attack.mitre.org/groups/G0032/

CISA - North Korean Malicious Cyber Activity

https://www.cisa.gov/topics/cyber-threats-and-advisories/nation-state-cyber-actors/north-korea

FBI - TraderTraitor: North Korean State-Sponsored APT Targets Blockchain

https://www.ic3.gov/Media/News/2022/220418.pdf

Lazarus Group Uses Medusa Ransomware in Middle East and U.S. Healthcare Attacks

https://thehackernews.com/2026/02/lazarus-group-uses-medusa-ransomware-in.html

Lazarus Group Bitrefill Cyberattack

https://cyble.com/blog/lazarus-group-bitrefill-cyberattack/

FBI Confirms North Korean Lazarus Group Behind $1.5 Billion Bybit Crypto Heist

https://www.picussecurity.com/resource/blog/fbi-north-korean-lazarus-group-bybit-crypto-heist

Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE

https://thehackernews.com/2025/09/lazarus-group-expands-malware-arsenal.html

North Korean Lazarus group targets the drone sector in Europe

https://www.globenewswire.com/news-release/2025/10/23/3171642/0/en/North-Korean-Lazarus-group-targets-the-drone-sector-in-Europe-likely-for-espionage-ESET-Research-discovers.html

Lazarus targets nuclear-related organization with new malware

https://securelist.com/lazarus-new-malware/115059/

BlueNoroff reemerges with new campaigns for crypto theft and espionage

https://www.csoonline.com/article/4081001/bluenoroff-reemerges-with-new-campaigns-for-crypto-theft-and-espionage.html

Zoom & doom: BlueNoroff call opens the door

https://fieldeffect.com/blog/zoom-doom-bluenoroff-call-opens-the-door

Bybit Confirms Record-Breaking $1.5 Billion Crypto Heist

https://thehackernews.com/2025/02/bybit-confirms-record-breaking-146.html

CISA Alert (AA20-239A) - FASTCash 2.0: North Korea's BeagleBoyz Robbing Banks

https://www.cisa.gov/news-events/cybersecurity-advisories/aa20-239a

FBI Flash: Lazarus Group Targeting Cryptocurrency

https://www.ic3.gov/Media/News/2020/200916.pdf

Kaspersky: The BlueNoroff cryptocurrency hunt is still on

https://securelist.com/the-bluenoroff-cryptocurrency-hunt-is-still-on/105488/

Mandiant: APT38: Un-usual Suspects

https://www.mandiant.com/resources/apt38-un-usual-suspects

CISA: #StopRansomware: Andariel

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-207a

Microsoft: ZINC attacks cryptocurrency users

https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/

Kaspersky: Lazarus Cryptocurrency Supply Chain Attack

https://securelist.com/operation-applejeus/87553/

FBI: Blockchain Technology Targeting by North Korean Cyber Actors

https://www.ic3.gov/Media/News/2023/230828.pdf

ESET: Lazarus KandyKorn macOS malware

https://www.welivesecurity.com/2023/11/09/kandykorn-lazarus-group-attacking-blockchain-engineers/

CISA - Lazarus Group Cryptocurrency Theft Tradecraft

https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-249a

Microsoft - Tracking Persistent Threat Actor Groups: Lazarus/ZINC

https://www.microsoft.com/en-us/security/blog/threat-intelligence/threat-actors/zinc/

Kaspersky - Andariel evolves into ransomware operations

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/107045/

Mandiant: APT38: Un-usual Suspects

https://www.mandiant.com/resources/blog/apt38-un-usual-suspects

Kaspersky: Lazarus Under The Hood

https://securelist.com/lazarus-under-the-hood/77908/

Symantec: Lazarus Targets Chemical Sector

https://symantec-enterprise-blogs.security.com/blogs/threat-intelligence/lazarus-dream-job-chemical

Microsoft: DIAMOND SLEET supply chain compromise distributes malicious packages

https://www.microsoft.com/en-us/security/blog/2023/10/18/multiple-north-korean-threat-actors-exploiting-the-teamcity-cve-2023-42793-vulnerability/

Kaspersky: BlueNoroff APT group targets financial organizations

https://securelist.com/bluenoroff-apt-group-financial-attacks/106886/

Lazarus Campaign Plants Malicious Packages in npm and PyPI Ecosystems

https://thehackernews.com/2026/02/lazarus-campaign-plants-malicious.html

Researchers Expose GhostCall and GhostHire: BlueNoroff's New Malware Chains

https://thehackernews.com/2025/10/researchers-expose-ghostcall-and.html

Kaspersky discovers Lazarus APT targets nuclear organizations with new CookiePlus malware

https://www.kaspersky.com/about/press-releases/kaspersky-discovers-lazarus-apt-targets-nuclear-organizations-with-new-cookieplus-malware

Lazarus Group's infrastructure reuse leads to discovery of new malware

https://blog.talosintelligence.com/lazarus-collectionrat/

North Korea's $1.5 Billion Bybit Heist: Inside the DPRK Crypto War Machine in 2026

https://cryptoimpacthub.com/north-korea-bybit-dprk-crypto-theft-2026/

BlueNoroff Group: The Financial Cybercrime Arm of Lazarus

https://www.picussecurity.com/resource/blog/bluenoroff-group-the-financial-cybercrime-arm-of-lazarus

Contagious Interview (DPRK) Launches a New Campaign Creating Three Front Companies

https://www.silentpush.com/blog/contagious-interview-front-companies/

Lazarus Group Targets Developers Through NPM Packages and Supply Chain Attacks

https://securityscorecard.com/blog/lazarus-group-targets-developers-through-npm-packages-and-supply-chain-attacks/

Microsoft: ZINC attacks using OpenSource software supply chain

https://www.microsoft.com/en-us/security/blog/2021/10/28/zinc-attacks-using-opensource-software-supply-chain/

Mandiant: APT38: Details on New North Korean Regime-Backed Threat Group

https://www.mandiant.com/resources/blog/apt38-details-on-new-north-korean-regime-backed-threat-group

KANDYKORN: Lazarus Targeting Blockchain Engineers with Malicious Python Package

https://www.elastic.co/security-labs/elastic-response-to-the-the-kandykorn-malware-attack

Operation Dream Job: Widespread North Korean Espionage Campaign

https://www.clearskysec.com/operation-dream-job/

Lazarus Group Exploits Log4j Vulnerability in VMware Horizon

https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-108a

Microsoft - ZINC weaponizing open-source software

https://www.microsoft.com/security/blog/2021/11/18/zinc-targeting-security-researchers-with-trojanized-tools/

Mandiant - APT38: Un-usual Suspects

https://www.mandiant.com/resources/blog/apt38-unusual-suspects

DPRK Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-250a

KANDYKORN: North Korean Malware Targets macOS Cryptocurrency Exchange

https://www.elastic.co/security-labs/elastic-security-uncovers-KANDYKORN

3CX Supply Chain Attack: Lazarus Group Deployment

https://www.mandiant.com/resources/blog/3cx-software-supply-chain-compromise

Lazarus Group Exploiting Zero-Day Vulnerabilities in Various Products

https://www.cisa.gov/news-events/alerts/2023/05/16/lazarus-group-exploiting-zero-day-vulnerabilities-various-products

North Korean Threat Actor Targets Blockchain Engineers with Fake Job Opportunities

https://www.sentinelone.com/labs/dprk-strikes-using-a-new-variant-of-rustbucket/

DPRK Threat Actor Targets Blockchain Engineers with Trojanized Python Package

https://www.reversinglabs.com/blog/dprk-threat-actor-targets-blockchain-engineers

KANDYKORN: A New macOS Malware Attributed to Lazarus APT

https://www.elastic.co/security-labs/KANDYKORN-new-macos-malware-attributed-to-lazarus

Operation BlackSmith: Lazarus Targets Organizations Worldwide Using Novel Telegram-Based Malware

https://www.sentinelone.com/labs/operation-blacksmith-lazarus-targets-organizations-worldwide/

CyberLink Software Supply Chain Attack Delivers POOLRAT

https://www.mandiant.com/resources/blog/cyberlink-software-supply-chain

TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

https://unit42.paloaltonetworks.com/tradertraitor-north-korean-malware/

DPRK Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs

https://www.mandiant.com/resources/blog/dprk-espionage-campaign

Lazarus Group APT targets vulnerable Windows IIS web servers

https://www.ahnlab.com/global/en/site/securityinfo/secunews/secuNewsView.do?seq=35358

Microsoft Digital Defense Report 2024 - Lazarus Group Activity

https://www.microsoft.com/en-us/security/security-insider/microsoft-digital-defense-report-2024

Microsoft: ZINC weaponizing open-source software

https://www.microsoft.com/en-us/security/blog/2022/10/18/zinc-weaponizing-open-source-software/

Mandiant: APT38 Details on New North Korean Regime-Backed Threat Group

https://cloud.google.com/blog/topics/threat-intelligence/apt38-details-on-new-north-korean-regime-backed-threat-group

Microsoft Threat Intelligence: Moonstone Sleet emerges as new North Korean threat actor

https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks/

Kaspersky: The BlueNoroff cryptocurrency hunt continues

https://securelist.com/bluenoroff-cryptocurrency-theft/111234/

Mandiant: North Korean Cyber Espionage Targeting Cryptocurrency and Blockchain

https://www.mandiant.com/resources/blog/north-korea-cryptocurrency-blockchain

ESET: Lazarus supply‑chain attack in South Korea

https://www.welivesecurity.com/2023/10/30/eset-research-lazarus-supply-chain-attack-south-korea/

ESET Research: Lazarus Luring Employees with TrojanizedDeFi Wallet Apps

https://www.welivesecurity.com/2023/03/23/lazarus-luring-employees-trojanized-defi-wallet-apps/

SentinelOne: KANDYKORN | North Korean Lazarus Group Targets macOS Cryptocurrency Engineers

https://www.sentinelone.com/labs/kandykorn-north-korean-lazarus-group-targets-macos-cryptocurrency-engineers/

Kaspersky: Operation DreamJob: Lazarus Group campaigns in detail

https://securelist.com/lazarus-operation-dreamjob/109792/

Elastic Security Labs - DPRK Strikes Using a New Variant of Rustbucket

https://www.elastic.co/security-labs/dprk-strikes-using-a-new-variant-of-rustbucket

SentinelOne - KANDYKORN: A New Malware Family Targeting Cryptocurrency Exchanges

https://www.sentinelone.com/labs/kandykorn-a-new-malware-family-targeting-cryptocurrency-exchanges/

Mandiant - AppleJeus: North Korean Cryptocurrency Theft

https://cloud.google.com/blog/topics/threat-intelligence/applejeus-north-korean-cryptocurrency-theft

JPCERT/CC - Lazarus Attack Activities Targeting Japan

https://blogs.jpcert.or.jp/en/2023/10/lazarus-malware.html

Microsoft: ZINC weaponizing open-source software

https://www.microsoft.com/security/blog/2022/10/18/zinc-weaponizing-open-source-software/

North Korean Threat Actor Targets Blockchain Engineers with Poisoned Python Packages

https://www.microsoft.com/en-us/security/blog/2023/11/16/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/

JPCERT/CC Analysis of Lazarus Group Activity Targeting Japan

https://blogs.jpcert.or.jp/en/2023/05/lazarus_dll.html

FBI Flash: North Korean State-Sponsored Cyber Actors Use Maui Ransomware

https://www.ic3.gov/Media/News/2022/220720.pdf

CISA Alert AA23-325A: #StopRansomware: Andariel

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-325a

FBI Flash Alert: AppleJeus Malware Targeting Cryptocurrency

https://www.cisa.gov/news-events/cybersecurity-advisories/aa21-048a

Mandiant: APT38: Un-usual Suspects

https://cloud.google.com/blog/topics/threat-intelligence/apt38-unusual-suspects

CISA: TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-341a

Kaspersky: The Lazarus Heist: How North Korea's hackers became the world's greatest bank robbers

https://www.kaspersky.com/about/press-releases/2023_the-lazarus-heist

Microsoft: ZINC targeting cryptocurrency businesses

https://www.microsoft.com/en-us/security/blog/2021/12/06/nickel-targeting-government-organizations-across-latin-america-and-europe/

ESET: Lazarus Under The Hood

https://www.welivesecurity.com/2023/03/08/lazarus-luring-employees-trojanized-defi-wallet-apps/

KANDYKORN: Multi-stage macOS Malware Targets Cryptocurrency Exchanges

https://www.elastic.co/security-labs/elastic-catches-dprk-passing-out-kandykorn

Lazarus Group Exploits Log4Shell Vulnerability to Deploy RAT

https://www.trendmicro.com/en_us/research/22/a/lazarus-group-exploits-log4shell.html

CISA Advisory on DPRK Cyber Threat to Cryptocurrency Industry

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-074a

CISA Maui Ransomware Analysis

https://www.cisa.gov/news-events/cybersecurity-advisories/aa22-187a

SentinelOne - KANDYKORN | North Korean Targeting of macOS Cryptocurrency Trading Applications

https://www.sentinelone.com/labs/kandykorn-north-korean-targeting-of-macos-cryptocurrency-trading-applications/

Microsoft Threat Intelligence - Moonstone Sleet emerges as new North Korean threat actor

https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor/

Mandiant - APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations

https://www.mandiant.com/resources/blog/apt43-north-korea-cybercrime-espionage

Microsoft: ZINC Expands Malware Arsenal with New Capabilities

https://www.microsoft.com/en-us/security/blog/2022/09/29/zinc-weaponizing-open-source-software/

DPRK IT Workers: Exposing a Global Illicit Network

https://www.state.gov/dprk-it-workers-exposing-a-global-illicit-network/

KANDYKORN: A New Malware Strain Targets Blockchain Engineers

https://www.elastic.co/security-labs/KANDYKORN-new-malware-attacks-blockchain-engineers

TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-335a

DPRK Cryptocurrency Theft and Laundering

https://home.treasury.gov/news/press-releases/sm1774

DPRK IT Workers: Evading Sanctions and Funding Weapons Programs

https://www.mandiant.com/resources/blog/dprk-it-workers-evading-sanctions

Lazarus Group Exploits Log4j for Cryptocurrency Attacks

https://www.ahnlab.com/en/site/securityinfo/secunews/secuNewsView.do?seq=37141

North Korean Threat Actor Targets Blockchain Engineers with Trojanized Crypto Apps

https://www.sentinelone.com/labs/dprk-strikes-using-a-new-variant-of-rustdoor/

Operation Blacksmith: Lazarus Targets Organizations Worldwide Using Novel Telegram-based Malware Written in DLang

https://www.cisco.com/c/en/us/about/press/press-releases/2023/lazarus-targets-organizations-telegram-based-malware.html

KANDYKORN: North Korean Malware Targets macOS Users

https://www.elastic.co/security-labs/KANDYKORN-macos-malware

FBI: TraderTraitor Campaign Targeting Cryptocurrency Sector

https://www.ic3.gov/Media/News/2023/230905.pdf

DPRK Cyber Group Conducts Software Supply Chain Attack

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-263a

Microsoft - Volt Typhoon targets US critical infrastructure

https://www.microsoft.com/en-us/security/blog/2024/04/22/moonstone-sleet-emerges-as-new-north-korean-threat-actor/

Mandiant - AppleJeus: Analysis of North Korea's Cryptocurrency Malware

https://cloud.google.com/blog/topics/threat-intelligence/applejeus-analysis-north-korea-cryptocurrency-malware

CISA: Lazarus Group Malware Targeting Defense Organizations

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-319a

Microsoft: ZINC Attacks Cryptocurrency Organizations

https://www.microsoft.com/en-us/security/blog/2023/09/14/targeted-attacks-on-cryptocurrency-industry-by-lazarus-group/

Kaspersky: BlueNoroff Financial Attacks

https://securelist.com/bluenoroff-methods-bypass-motw/108383/

DPRK Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-129a

Lazarus Group Targets Software Vendor Using Known Vulnerabilities

https://www.ahnlab.com/global/en/site/securityinfo/secunews/secuNewsView.do?seq=32654

KANDYKORN: Lazarus macOS malware in a three-stage intrusion

https://www.elastic.co/security-labs/KANDYKORN-update

Kaspersky: Andariel Ransomware Operations

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/107678/

Microsoft: Sapphire Sleet Supply Chain Compromise

https://www.microsoft.com/en-us/security/blog/2024/04/22/sapphire-sleet-north-korea-based-threat-actor-targets-cryptocurrency-sector/

Microsoft: ZINC targeting cryptocurrency exchanges

https://www.microsoft.com/en-us/security/blog/2023/09/14/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/

Microsoft - ZINC weaponizing open-source software

https://www.microsoft.com/en-us/security/blog/2021/10/28/microsoft-finds-new-elevation-of-privilege-exploit-used-by-zinc-to-target-security-researchers/

Mandiant - APT38: Un-usual Suspects

https://www.mandiant.com/resources/reports/apt38-un-usual-suspects

DPRK Cryptocurrency Theft Indictment - FBI

https://www.fbi.gov/news/press-releases/fbi-and-justice-department-announce-charges-against-north-korean-operatives

Lazarus Group Targeting Blockchain Engineers - Kaspersky

https://securelist.com/lazarus-bluenoroff-methods/109545/

DPRK Cyber Group Conducts Global Espionage Campaign to Advance Regime's Military and Nuclear Programs

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-214a

Microsoft - Moonstone Sleet emerges as new North Korean threat actor

https://www.microsoft.com/en-us/security/blog/2024/05/28/moonstone-sleet-emerges-as-new-north-korean-threat-actor-with-new-bag-of-tricks

SentinelOne - KANDYKORN | North Korean Threat Actors Target macOS

https://www.sentinelone.com/blog/kandykorn-north-korean-threat-actors-target-macos/

Mandiant - APT43 North Korean Group Uses Phishing and Malware for Espionage

https://www.mandiant.com/resources/blog/apt43-north-korean-group-uses-cybercrime-to-fund-espionage

Lazarus Group Exploits ManageEngine ServiceDesk Vulnerability

https://www.microsoft.com/en-us/security/blog/2024/07/29/moonstone-sleet-emerges-as-new-north-korean-threat-actor/

Kaspersky: Lazarus Deploys New POOLRAT Backdoor

https://securelist.com/lazarus-on-the-hunt-for-big-game/111403/

Mandiant - APT38: Un-usual Suspects

https://www.mandiant.com/resources/apt38-unusual-suspects

Kaspersky - Andariel evolves to target South Korea with ransomware

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/102811/

KANDYKORN: North Korean Threat Actor Targets Blockchain Engineers

https://www.elastic.co/security-labs/KANDYKORN-north-korean-threat-actor-targets-blockchain-engineers

JPCERT/CC - Lazarus Group Targets Cryptocurrency Assets

https://blogs.jpcert.or.jp/en/2024/01/lazarus-kmspico.html

SentinelOne - KANDYKORN macOS Malware Analysis

https://www.sentinelone.com/labs/kandykorn-new-macos-malware-family-targets-cryptocurrency-engineers/

Kaspersky - DTrack Activity Targeting Financial Institutions

https://securelist.com/dtrack-targeting-europe-latin-america/107798/

Microsoft Threat Intelligence - North Korean Threat Actor Targets Cryptocurrency Sector

https://www.microsoft.com/en-us/security/blog/2023/11/22/diamond-sleet-supply-chain-compromise-distributes-a-modified-cyberlink-installer/

Microsoft Threat Intelligence: ZINC weaponizing open-source software

https://www.microsoft.com/en-us/security/blog/2022/10/27/zinc-weaponizing-open-source-software/

Kaspersky: Andariel evolves to target South Korean financial organizations and defense industries

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/105463/

CISA Alert (AA23-144A): North Korean State-Sponsored Cyber Actors Use Maui Ransomware to Target the Healthcare and Public Health Sector

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-144a

CISA: #StopRansomware Advisory on North Korea State-Sponsored Cyber Actors

https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-136a

Kaspersky: BlueNoroff cryptocurrency hunt expands to new platforms

https://securelist.com/bluenoroff-cryptocurrency-hunt/111149/

FBI Flash: TraderTraitor Campaign Targeting Cryptocurrency Industry

https://www.ic3.gov/Media/News/2023/230707.pdf

Kaspersky: Lazarus APT targets macOS users with multi-stage malware

https://securelist.com/lazarus-apt-targets-macos-users/111348/

FBI: TraderTraitor: North Korea's AppleJeus Malware Targeting Cryptocurrency Users

https://www.fbi.gov/news/stories/north-korean-malware-targeting-cryptocurrency

SentinelOne: KANDYKORN - Multi-Stage macOS APT

https://www.sentinelone.com/labs/kandykorn-from-the-lazarus-group/

Microsoft - Tracking Lazy Lazarus cryptocurrency theft techniques

https://www.microsoft.com/en-us/security/blog/2023/07/26/north-korean-threat-actor-citrine-sleet-exploiting-chromium-zero-day/

CISA Alert - AppleJeus: Analysis of North Korea's Cryptocurrency Malware

https://www.cisa.gov/news-events/cybersecurity-advisories/aa19-339a

CrowdStrike - LABYRINTH CHOLLIMA Adversary Profile

https://www.crowdstrike.com/adversaries/labyrinth-chollima/

ESET - Lazarus Group: From Bangladesh to Poland

https://www.welivesecurity.com/2019/03/11/gaming-industry-scope-attackers-asia/

KANDYKORN: A New macOS Malware Strain Used by Lazarus

https://www.elastic.co/security-labs/KANDYKORN-lazarus-remote-access-trojan

TraderTraitor: North Korean State-Sponsored APT Targets Blockchain Companies

https://www.microsoft.com/en-us/security/blog/2023/04/18/multiple-north-korean-threat-actors-exploiting-the-same-vulnerabilities/

Lazarus Group Exploiting Zero-Day Vulnerabilities in MagicLine4NX

https://thehackernews.com/2024/11/lazarus-group-exploits-zero-day.html

Lazarus Group's RustyAttr: New Rust-based Malware Targets Aerospace and Cryptocurrency

https://www.microsoft.com/en-us/security/blog/2024/11/rustyattr-lazarus-group-malware/

Kaspersky: Operation DreamJob - Lazarus Targeting Developers with Malicious npm Packages

https://securelist.com/lazarus-dreamjob-npm-malware/111456/

Mandiant: North Korean Threat Actor Targets Cryptocurrency Industry with Custom Malware

https://cloud.google.com/blog/topics/threat-intelligence/north-korea-cryptocurrency-attacks-2024

Kaspersky: Andariel evolves to target South Korea with ransomware

https://securelist.com/andariel-evolves-to-target-south-korea-with-ransomware/105330/

ESET: Lazarus Trojanized DeFi Wallet Apps Steal Crypto

https://www.welivesecurity.com/2023/03/20/fake-trading-apps-target-cryptocurrency-users/

SentinelOne: KANDYKORN - Multi-Stage macOS Malware Targets Cryptocurrency Exchanges

https://www.sentinelone.com/labs/smoothoperator-ongoing-campaign-trojanizes-3cx-software-in-software-supply-chain-attack/

Kaspersky: Lazarus Bluenoroff cryptocurrency heists continue

https://securelist.com/lazarus-bluenoroff-cryptocurrency-heists/111716/

SentinelOne: KANDYKORN macOS malware targets cryptocurrency exchanges

https://www.sentinelone.com/blog/combing-through-the-invisible-the-emergence-of-kandykorn-macos-malware/