Researchers reported that the North Korea-linked Lazarus Group conducted Amazon-themed phishing campaigns targeting victims in the Netherlands and Belgium. The operation used lures impersonating Amazon to trick recipients into opening malicious content, continuing Lazarus’s pattern of blending social engineering with malware delivery to gain access to targeted systems.
The activity highlights Lazarus’s use of trusted consumer brands to improve the credibility of phishing emails and increase the likelihood of compromise. By tailoring the campaign to local targets in Western Europe, the attackers demonstrated a focused effort to harvest credentials or deploy malware through convincing retail-themed messages tied to Amazon branding.

Get the infrastructure and lures behind it.
1 event from the most recent confirmed update back to the earliest known activity.
ESET publicly reported on Amazon-themed campaigns attributed to the Lazarus Group targeting victims in Belgium and the Netherlands. The reference provides no earlier dated events, so the publication date is used as the event date.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
1 reference tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.