Sansec reported that North Korean hackers were skimming payment data from U.S. and European online shoppers in a Magecart-style campaign, reviving scrutiny of earlier compromises at retailers including FocusCamera and PaperSource. A prior Walmart Global Tech analysis of those incidents said the affected environments appeared to show signs of earlier TrickBot activity and argued that the public attribution to Lazarus relied heavily on infrastructure overlap, particularly reused LeaseWeb IP space, which by itself was presented as weak evidence.
SentinelLabs' later research on TrickBot's Anchor project adds context to that dispute by describing Anchor as a stealthier, APT-like framework used for targeted intrusions and noting that it incorporated PowerRatankba, a tool previously associated with Lazarus. Taken together, the reporting points to either a misattributed skimming operation conducted by TrickBot-linked actors or a more consequential scenario in which Lazarus operated inside networks previously compromised by TrickBot/Anchor, underscoring the blurred line between financially motivated crimeware and state-linked intrusion tradecraft.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
On 2020-07-06, Sansec reported that a North Korea-linked group identified as Lazarus or HIDDEN COBRA was conducting Magecart-style web-skimming attacks against websites, including PaperSource and FocusCamera.
The SentinelLabs report says international law enforcement charged or indicted Dridex botnet operators and imposed sanctions in December 2019, naming Maksim Yakubets and Igor Turashev among those associated with the operation.
The Walmart Global Tech article states that FocusCamera was initially compromised by TrickBot around October 2019, before later activity involving PowerTrick in the environment.
The SentinelLabs report states that TrickBot was developed in 2016 as banking malware, with early public reporting appearing in fall 2016. It says the malware was already tested and functional by November 2016 and initially targeted Australian banks before expanding to other countries.
According to the Walmart Global Tech article quoting Sansec, the malware was removed within 24 hours from an affected store and resurfaced on the same store a week later, suggesting the attackers may have retained access.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
4 references tracked. Mallory keeps watching after this page renders.
labs.sentinelone.com
Open sourcesentinelone.com
Open sourcesansec.io
Open sourcemedium.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.