Skip to main content
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligenceremote-access-implantidentity-impersonation-fraud

North Korea-Linked Threat Activity and Reporting on Lazarus, IT Worker Schemes, and Related Malware

Updated 7d agoFirst seen Mar 11, 202635 sources

Multiple reports and threat-intel posts highlighted North Korea-linked cyber activity spanning social engineering, malware, and broader ecosystem analysis. AllSecure described an attempted compromise of a CEO via a fake LinkedIn job interview attributed to Lazarus tradecraft (tagged BeaverTail / Contagious Interview), indicating continued use of recruiter-style lures and developer tooling themes (e.g., VSCode) to gain execution on target systems. Separately, eSentire published technical analysis on the DEV#POPPER remote access trojan and associated OmniStealer activity, framing it as DPRK-linked malware and providing defensive guidance for organizations facing this threat class.

Additional DPRK-focused intelligence covered both strategic and operational dimensions. Google’s Cloud Threat Horizons Report H1 2026 discussed cloud-focused threat activity and tracked DPRK-linked clusters (including UNC4899 and UNC5267), while Logpresso published an OSINT report on DPRK remote IT worker infiltration tactics (fraudulent employment/contractor placement). NKInternet released a catalog-style overview of North Korea’s software export ecosystem, and RedAsgard’s “Hunting Lazarus” series contributed hands-on investigative detail into Lazarus operator artifacts. A separate Lazarus threat-actor profile page aggregated historical reporting and statistics, but did not add a discrete new incident beyond compilation.

Share:
North Korea-Linked Threat Activity and Reporting on Lazarus, IT Worker Schemes, and Related Malware
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

34 events from the most recent confirmed update back to the earliest known activity.

34 EVENTS
May 28, 20268d ago

Wiz publishes report on threat actor targeting crypto organizations

A Bluesky post shared a Wiz publication titled "Threat Actor Targets Crypto Organizations," associated in the reference with JINX-0164, suspected DPRK-linked activity, and macOS targeting. The available reference provides only the report title and topical tags, without additional technical details, victims, or indicators.

Post by @lazarusholic.bsky.social - Bluesky
May 25, 202611d ago

RedAsgard publishes developer safety checklist on fake coding interviews

RedAsgard published an article titled "A Fake Coding Interview Is an Execution Request: Developer Safety Checklist," covering developer-targeted social engineering associated with fake coding interviews and Lazarus-linked tradecraft. The reference ties the article to themes including GitHub, npm, VSCode, and DPRK cyber threat intelligence.

@lazarusholic.bsky.social on Bluesky
May 23, 202613d ago

RedAsgard publishes Hunting Lazarus Part IX: The Google Mirror

A Bluesky post shared RedAsgard's blog article "Hunting Lazarus Part IX: The Google Mirror," indicating a new Lazarus-focused threat intelligence publication. The available reference ties the report to BeaverTail, OtterCookie, and DPRK cyber threat intelligence themes but provides no additional technical details beyond the report title and topic tags.

Post by @lazarusholic.bsky.social - Bluesky
May 22, 202614d ago

Fox-IT publishes report on Lazarus RemotePE malware

A Fox-IT report titled "RemotePE: The Lazarus RAT that lives in memory" was publicly shared, associating the RemotePE malware family with the Lazarus threat actor. The available reference provides only the report title and broad Lazarus/DPRK context, without additional technical details beyond the report’s existence and topic.

Post by @lazarusholic.bsky.social - Bluesky

Trend Micro publishes analysis of Void Dokkaebi InvisibleFerret malware

Trend Micro published a research article titled "Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware." The reference links InvisibleFerret to the DPRK-associated Void Dokkaebi activity cluster, but provides no further technical details beyond the report title and topic.

Post by @lazarusholic.bsky.social - Bluesky

Bitso publishes "Interview with the Chollima VIII" article

Bitso published an article titled "Interview with the Chollima VIII," focused on DPRK IT worker activity and cyber threat intelligence. The available reference is a Bluesky post sharing the article and provides no additional technical details, victims, or indicators beyond the article's existence and topic.

Post by @lazarusholic.bsky.social - Bluesky
May 19, 202617d ago

Krypt3ia publishes report on DPRK activity evolution through campaign linkage

Krypt3ia published a threat intelligence report titled "DPRK Activity Evolution Through Campaign Linkage," focused on North Korean cyber activity and relationships across campaigns. The available reference provides only the report title and broad themes including cryptocurrency, IT workers, supply chain, and CTI.

Post by @lazarusholic.bsky.social - Bluesky
May 18, 202618d ago

meowmfer publishes report on active GitHub network in Contagious Interview

A Bluesky post shared meowmfer's report titled "Deep Dive into Active Github Network Running Contagious Interview," describing reporting on infrastructure tied to the DPRK-linked Contagious Interview campaign. The reference links the report to BeaverTail and OmniStealer themes but provides no further technical details beyond the report title and topic tags.

Post by @lazarusholic.bsky.social - Bluesky
May 17, 202619d ago

RedAsgard publishes Hunting Lazarus Part VIII on OtterCookie

A Bluesky post shared RedAsgard's blog article "Hunting Lazarus Part VIII: OtterCookie," indicating a new Lazarus-focused threat intelligence publication centered on the OtterCookie malware or campaign. The available reference does not include the article's substantive technical findings beyond its existence and topic.

Post by @lazarusholic.bsky.social - Bluesky
May 15, 202621d ago

Arkham research on Lazarus Group on-chain footprint is shared

A Bluesky post shared a new Arkham research article focused on the Lazarus Group's on-chain footprint and money-laundering activity, with AppleJeus and DPRK cyber threat intelligence themes. The reference indicates the report was being publicly promoted on 2026-05-15.

Post by @lazarusholic.bsky.social - Bluesky
May 13, 202623d ago

Researcher alleges DPRK recruiter offered payment to launder Upwork identity

A Bluesky post alleged that a North Korean recruiter attempted to pay someone $300 per month to launder an Upwork identity. The claim adds a specific example of suspected DPRK IT worker tradecraft involving freelance-platform identity misuse, though no independent confirmation or technical evidence is provided in the reference.

Post by @lazarusholic.bsky.social - Bluesky
May 11, 202625d ago

Researcher alleges suspected DPRK IT worker was employed at THORSwap

A Bluesky post by meowmfer alleged that a suspected DPRK IT worker had been employed at THORSwap. The reference provides only a brief claim and an archived link, without technical evidence, access details, or independent confirmation.

Post by @lazarusholic.bsky.social - Bluesky
May 7, 202629d ago

NISOS publishes report on DPRK employment fraud targeting crypto companies

NISOS published a report titled "DPRK Employment Fraud Targeting Crypto Companies," describing North Korean employment fraud activity aimed at cryptocurrency firms. The available reference is a Bluesky post sharing the report and ties it to DPRK IT worker threat intelligence.

Post by @lazarusholic.bsky.social - Bluesky
May 4, 20261mo ago

Kmsec publishes report on DPRK abuse of Cloudflare Workers and Pages

A report attributed to Kmsec on North Korea's abuse of Cloudflare Workers and Cloudflare Pages was publicly shared. The available reference links the topic to DPRK cyber activity but does not provide underlying technical details, victims, or indicators beyond the report's existence and focus.

Post by @lazarusholic.bsky.social - Bluesky
Apr 27, 20261mo ago

NKInternet reports fake dev and company entities vexxloso and Nixsora.com

NKInternet published an article titled "More Fake Devs, More Fake Companies: vexxloso and Nixsora.com," adding reporting on suspected DPRK-linked fake developer and fake company activity. The available reference identifies the named entities and ties the article to North Korean IT worker threat intelligence, but provides no further technical details or victim information.

Post by @lazarusholic.bsky.social - Bluesky
Apr 23, 20261mo ago

Expel publishes report on Lazarus using AI to target developers

Expel published an article titled "Inside Lazarus: How North Korea uses AI to industrialize attacks on developers," describing Lazarus-linked activity focused on developers. The available reference is a Bluesky post sharing the report and does not provide additional technical details, victims, or indicators beyond the report’s existence and topic.

Post by @lazarusholic.bsky.social - Bluesky
Apr 22, 20261mo ago

Trend Micro reports Void Dokkaebi fake interview malware campaign

Trend Micro published a report titled "Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories," describing a DPRK-linked campaign that used fake job interview lures and code repositories in the infection chain. The available reference is a social media post sharing the report and does not provide additional victim, indicator, or malware-behavior details.

Post by @lazarusholic.bsky.social - Bluesky
Apr 21, 20261mo ago

NoxHunt publishes report on DPRK IT workers' computers

A NoxHunt article titled "Inside the computers of DPRK IT workers" was publicly shared, indicating new reporting focused on North Korean IT worker activity. The available reference includes only the title and topic tags, without technical findings or victim details.

Post by @lazarusholic.bsky.social - Bluesky
Apr 20, 20262mo ago

FalconFeeds reports UNC1069 deepfake campaign targeting crypto and supply chains

FalconFeeds published a report titled "UNC1069: DPRK’s Deepfake-Driven Cyber Campaign Targeting Crypto and Software Supply Chains." The report characterized UNC1069 as a North Korea-linked operation using deepfake-enabled social engineering and highlighted targeting of cryptocurrency organizations and software supply chains.

Post by @lazarusholic.bsky.social - Bluesky
Apr 17, 20262mo ago

Researcher claims DPRK-linked IT worker cell infiltrated Tokamak Network

A Bluesky post attributed to meowmfer claimed to have mapped a cell of more than 14 accounts that allegedly infiltrated Tokamak Network. The post framed the activity in the context of DPRK-linked IT worker operations but provided no technical details on access methods, affected systems, or independent confirmation.

Post by @lazarusholic.bsky.social - Bluesky
Apr 8, 20262mo ago

SecurityAlliance publishes UNC1069 advisory on fake Teams and Zoom calls

SecurityAlliance published an advisory on DPRK-linked activity tracked as UNC1069. The advisory highlighted social-engineering lures involving fake Microsoft Teams and Zoom calls.

Post by @lazarusholic.bsky.social - Bluesky

Socket reports Contagious Interview campaign spreading across five ecosystems

A Socket article reported that North Korea’s Contagious Interview campaign had spread across five ecosystems and was delivering staged remote access trojan payloads. The reference does not provide further technical details, victims, or indicators beyond the article’s existence and scope.

Post by @lazarusholic.bsky.social - Bluesky

NKInternet publishes article on npm malware, fake developers, and deepfakes

NKInternet published an article titled "npm Malware, Fake Devs, and Deepfake Videos: These Are A Few of My Favorite DPRK Things," covering DPRK-linked themes including npm ecosystem abuse, fake developers, and deepfake videos. The reference provides no additional technical details, victims, or indicators beyond the article's existence and topic.

Post by @lazarusholic.bsky.social - Bluesky
Apr 7, 20262mo ago

Walmart publishes "Mapping Ottercookie Infrastructure" report

Walmart published a cyber threat intelligence report titled "Mapping Ottercookie Infrastructure," focused on Ottercookie and DPRK-linked activity. The reference is a social media post sharing the report and does not provide additional technical details beyond the report’s existence and topic.

Post by @lazarusholic.bsky.social - Bluesky
Mar 26, 20262mo ago

eSentire publishes EtherRAT and EtherHiding technical analysis

eSentire released a report on EtherRAT and its SYS_INFO module, describing command-and-control activity using Ethereum-based infrastructure (EtherHiding), target selection logic, and beaconing designed to resemble CDN traffic. The report was publicly shared on 2026-03-26.

Post by @lazarusholic.bsky.social - Bluesky
Mar 24, 20262mo ago

Sophos publishes research on NICKEL ALLEY strategy

Sophos published an article titled "NICKEL ALLEY strategy: Fake it ‘til you make it," covering North Korea-linked activity. The reference associates the report with themes including ClickFix, Contagious Interview, and PylangGhost.

Post by @lazarusholic.bsky.social - Bluesky
Mar 12, 20263mo ago

AhnLab releases February 2026 APT group trends report

AhnLab published its "February 2026 APT Group Trends Report" on the ASEC site. The reference indicates the report covered activity associated with groups including BlueNoroff, Lazarus, and Medusa.

U.S. Treasury sanctions facilitators of DPRK IT worker fraud

The U.S. Department of the Treasury announced sanctions against facilitators of North Korean IT worker fraud targeting U.S. businesses. Related coverage also highlighted OFAC action involving DPRK IT workers' use of cryptocurrency.

Mar 11, 20263mo ago

Allsecure discloses fake LinkedIn job interview targeting its CEO

Allsecure published an account of a North Korea-linked attempt to hack its CEO through a fake job interview on LinkedIn. The activity was associated in the reference with Lazarus ecosystem themes including BeaverTail, Contagious Interview, and VSCode.

NKInternet publishes North Korea software catalog article

NKInternet published an article titled "Made for Export: North Korea’s Software Catalog," covering North Korean software offerings. The exact publication date is not stated in the reference, but it was publicly available by 2026-03-11.

Mar 10, 20263mo ago

Google releases Cloud Threat Horizons Report H1 2026

Google published its "Cloud Threat Horizons Report H1 2026," which the reference associates with cloud threat intelligence involving UNC4899, UNC5267, and DPRK-linked activity. The report was being shared publicly on 2026-03-10.

Mar 9, 20263mo ago

Logpresso publishes OSINT report on disguised DPRK IT workers

Logpresso published a Korean-language report on OSINT analysis of North Korean IT workers obtaining employment under disguise. The linked blog post is explicitly dated 2026-03-09.

eSentire publishes analysis of DEV#POPPER and OmniStealer

eSentire released a blog post analyzing the DEV#POPPER remote access trojan and OmniStealer, framed as relevant to DPRK-linked activity. The write-up focused on understanding the malware and defensive guidance for organizations.

RedAsgard publishes Lazarus threat intelligence report

RedAsgard published "Hunting Lazarus, Part 5: Eleven Hours on His Disk," a threat intelligence report focused on the Lazarus Group. The reference indicates the report was available by 2026-03-09.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

North Korea-Linked Threat Activity and Reporting on Lazarus, IT Worker Schemes, and Related Malware | Mallory