Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'lazarus'

View all threats tagged with 'lazarus'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: lazarus

Threats Tagged 'lazarus'

Click on any threat for detailed analysis and mitigation recommendations

Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators
0

The Contagious Trader campaign is a sophisticated malware operation targeting cryptocurrency users, attributed to North Korea with high confidence. It involves malicious cryptocurrency trading bot projects on GitHub that exfiltrate sensitive data and private keys using various techniques, including malicious npm dependencies. The campaign demonstrates overlaps with known North Korean tactics, particularly those of FAMOUS CHOLLIMA, including the use of GitHub, npm, and Vercel infrastructure, Base64-encoded payload URLs, and anonymizing VPNs for npm package publishing. The operation represents a shift in tactics, expanding beyond the previous Contagious Interview campaign to target a broader range of cryptocurrency users.

Join the discussion
Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel PlatformsCVE-2023-42793
0

The Contagious Interview campaign is a coordinated cyber espionage operation by North Korean threat actors, notably linked to the Lazarus group, targeting the cryptocurrency sector. These actors actively monitor cyber threat intelligence platforms such as Validin, VirusTotal, and Maltrail to identify exposed infrastructure and new targets. They prioritize rapid deployment of malicious infrastructure over stealth and use social engineering techniques, including the ClickFix method, to trick victims into executing malware. Between January and March 2025, over 230 victims were engaged, demonstrating the campaign's scale and sophistication. Although no known exploits for CVE-2023-42793 have been observed in the wild, the campaign poses a medium severity threat. European cryptocurrency organizations, especially in countries with significant crypto markets and financial sectors, are at risk. Mitigation requires targeted monitoring of threat intelligence platforms, enhanced user training against social engineering, and rapid incident response capabilities.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Tag: lazarus
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses