Researchers reported multiple DPRK-linked intrusion campaigns tied to Lazarus and Kimsuky, highlighting new malware, refreshed delivery chains, and reusable infrastructure. Gen Digital identified Kimsuky using a new HttpTroy backdoor against a South Korean target via a fake VPN invoice ZIP and .scr dropper, while Lazarus targeted victims in Canada with an updated chain that used a new Comebacker variant to memory-load a new BLINDINGCAN RAT. Separate reporting also described Lazarus using fake hiring workflows and an NVIDIA-themed lure to trick victims into copying a malicious command that deployed credential theft tools, MeshAgent remote access, Python-based payloads, and cryptocurrency data theft components.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
20 events from the most recent confirmed update back to the earliest known activity.
Hunt.io reported that host 207.254.22[.]248 also operated a Mythic C2 server on port 7443 during August 2025, later tying it to Lazarus credential-theft infrastructure.
A certificate subject common name, "hwc-hwp-7779700," linked 12 IP addresses that had been exposed on port 3389 since January 2025. Hunt.io later found 10 of those 12 IPs directly associated with Lazarus malware on port 443.
The same host, 149.28.139[.]62, remained active with Quasar RAT on port 1888 into October 2023, reinforcing its role in the broader infrastructure cluster.
Hunt.io identified Quasar RAT activity on host 149.28.139[.]62 over port 1888 during a period later tied to Lazarus DeceptiveDevelopment infrastructure.
3CX's CISO summarized Mandiant's interim findings and identified Windows malware TAXHAUL and COLDCAT as involved in the compromise.
Reporting indicated that 3CX retained Mandiant to investigate and respond to the supply-chain compromise.
A CrowdStrike engineer first publicly reported the 3CX incident in a Reddit thread, bringing attention to the compromised desktop software.
A user in Georgia submitted an archive named HSBC job offer.pdf.zip to VirusTotal, containing a Linux payload tied to Lazarus's DreamJob activity. ESET said this submission occurred several days before the 3CX attack was publicly revealed.
In late March 2023, 3CX desktop applications for Windows and macOS were found to contain malicious code enabling arbitrary code download and execution on installed systems. Investigators determined 3CX had been compromised by external threat actors.
ESET telemetry first observed a trojanized 3CX macOS application that was part of the later-disclosed supply-chain compromise. The company noted it may have been distributed earlier.
ESET assessed the operators behind the 3CX supply-chain attack planned activity as early as December 2022, implying they likely obtained a foothold in 3CX's network in late 2022.
A pivot on an FRP binary hash revealed eight hosting instances serving the same 10 MB FRP binary on port 9999. The uniform setup suggested scripted or automated provisioning by the operators.
By pivoting on MailPassView and WebBrowserPassView hashes, Hunt.io uncovered open directories on 207.254.22[.]248, 149.28.139[.]62, and 154.216.177[.]215. These servers exposed large collections of credential-harvesting tools, Quasar RAT infrastructure, and offensive utilities aligned with Lazarus DeceptiveDevelopment activity.
Hunt.io identified an ELF sample on 23.27.140[.]49:8080 that behaved like the Lazarus-associated BADCALL backdoor seen in the 3CX supply-chain attack. The new Linux variant added a /tmp/sslvpn.log file to record timestamped malware activity.
A joint Hunt.io and Acronis Threat Research Unit investigation connected previously unlinked DPRK operational assets, including staging servers, credential-theft environments, FRP tunneling nodes, and certificate-linked infrastructure. The researchers said recurring infrastructure habits enabled pivots across Lazarus and Kimsuky activity.
Researchers identified an open directory at office-theme[.]com hosting four malicious Word documents with VBA macros. The documents used aerospace and defense-themed decoys and all deployed the same COMEBACKER-related payload chain.
Researchers observed Lazarus activity against two victims in Canada using a new Comebacker variant and a service-based wrapper that memory-loaded a new BLINDINGCAN RAT variant. The initial access vector was not observed, though phishing was assessed as likely.
Threat Labs researchers reported a Kimsuky intrusion against a single victim in South Korea using a ZIP archive masquerading as a VPN invoice or quotation. Executing the embedded .scr file launched a chain that installed Memload_V3 and the newly named HttpTroy backdoor.
Researchers identified a Lazarus-attributed multi-stage attack chain disguised as an NVIDIA-related update and delivered through a fake hiring assessment workflow. The malware stole browser and email credentials, installed MeshAgent, and harvested cryptocurrency-related data.
ESET reported a Lazarus Operation DreamJob campaign targeting Linux users with the OdicLoader downloader and SimplexTea backdoor. In the same report, ESET assessed with high confidence that Lazarus conducted the March 2023 3CX supply-chain attack.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
acronis.com
Open sourceenki.co.kr
Open sourcegendigital.com
Open sourcegendigital.com
Open sourcewelivesecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.