Google and Zscaler tied multiple intrusion campaigns to North Korean state-backed operators, including Lazarus-linked activity that targeted South Korean users, security researchers, cryptocurrency firms, fintech companies, IT organizations, and media entities. Google reported that two North Korean threat groups exploited the Chrome remote code execution flaw CVE-2022-0609 in campaigns associated with Operation Dream Job and Operation AppleJeus, and assessed that the groups likely worked for the same entity while sharing a common exploit supply chain. Google also said one campaign overlapped with an earlier operation aimed at security researchers, where attackers created the fake security company SecuriElite and used social engineering tied to browser exploitation.

See which actors are running it and whether you're in range.
14 events from the most recent confirmed update back to the earliest known activity.
Google patched the Chrome remote code execution vulnerability CVE-2022-0609 on February 14, 2022. The flaw had been actively exploited by North Korean government-backed groups.
On February 10, 2022, Google discovered two distinct North Korean government-backed threat groups exploiting Chrome vulnerability CVE-2022-0609. The campaigns targeted U.S.-based organizations in news media, IT, cryptocurrency, and fintech sectors.
Google said the earliest evidence of active deployment of the CVE-2022-0609 exploit kit dated to January 4, 2022. The exploit was used in campaigns associated with Operation Dream Job and Operation AppleJeus.
In 2022, the actor spoofed South Korean entities including KRNIC, Ahnlab, and Binance in phishing lures targeting users in South Korea. Zscaler said the campaign used macro-based documents and CHM files to deliver malware.
Passive DNS showed navercorpservice[.]com resolved to 172.93.201[.]253 in November 2021. Zscaler noted this IP was recently used to host disneycareers[.]net, another domain previously attributed to Lazarus.
Passive DNS showed navercorpservice[.]com resolved to 45.147.231[.]213 in September 2021. Zscaler later used this overlap with Lazarus-attributed infrastructure as part of its attribution case.
On March 17, 2021, the actors created a fake offensive security company named SecuriElite along with associated website and social media profiles to continue social engineering security researchers. Google linked this activity to a North Korean government-backed entity.
In 2021, the actor later attributed by Zscaler to Lazarus used credential-phishing emails posing as Naver to target South Korean users. Zscaler linked this activity to later malware campaigns through shared infrastructure and registrant data.
Google Threat Analysis Group said it had previously documented a North Korean government-backed campaign targeting security researchers in January 2021. That earlier campaign was later cited as overlapping with subsequent North Korean activity.
Zscaler reported that the IP address 45.147.231[.]213 hosted www.devguardmap[.]org in January 2021, a domain previously attributed to Lazarus. This historical infrastructure overlap later supported attribution of the South Korea-targeting campaign.
Zscaler ThreatLabz analyzed a long-running spear-phishing and malware campaign targeting users in South Korea and assessed with high confidence that it was associated with the Lazarus Group. The attribution was based on shared registrant emails, passive DNS overlaps, reused IP infrastructure, and links to previously reported Lazarus domains.
Dropbox took down malicious accounts used by the threat actor and shared threat intelligence with Zscaler ThreatLabz. Those accounts had been used by the malware to retrieve command-and-control infrastructure.
Google disclosed technical details of the CVE-2022-0609 exploitation campaigns 30 days after the patch release, in line with its disclosure policy. The company said the two groups likely worked for the same entity and shared a common exploit supply chain.
Google added the newly created SecuriElite website to Safe Browsing as a precaution, although it had not yet observed the site serving malicious content. Google also reported the identified social media profiles to the relevant platforms.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 122 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
3 references tracked. Mallory keeps watching after this page renders.
zscaler.com
Open sourceblog.google
Open sourceblog.google
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.