Lazarus, Kimsuky Conduct 58 Attacks Targeting South Korea


The North Korean hacking group Lazarus, affiliated with the Reconnaissance General Bureau, is strongly suspected to be behind a 4.45 billion Korean won hacking incident at the virtual asset exchange Upbit.

It has been confirmed that Lazarus carried out at least 31 hacking attacks over the past year. According to AhnLab’s “2025 Cyber Threat Trends & 2026 Security Outlook” report released on the 30th, Lazarus was the most frequently mentioned APT (Advanced Persistent Threat) group, with 31 activities recorded between October of last year and September of this year.

Read more…
Source: The Chosun Daily News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • APT43: North Korean Group Uses Cybercrime to Fund Espionage Operations

    March 28, 2023

    Mandiant researchers released a report on APT43, a prolific threat actor operating on behalf of the North Korean regime that they have observed engaging in cybercrime as a way to fund their espionage operations. According to Mandiant they track tons of activity throughout the year, but don’t always have enough evidence to attribute it to a ...

  • Kimsuky’s GoldDragon cluster and its C2 operations

    August 25, 2022

    Kimsuky (also known as Thallium, Black Banshee and Velvet Chollima) is a prolific and active threat actor primarily targeting Korea-related entities. Like other sophisticated adversaries, this group also updates its tools very quickly. In early 2022, Kaspersky researchers observed this group was attacking the media and a think-tank in South Korea and reported technical details ...

  • New GwisinLocker ransomware encrypts Windows and Linux ESXi servers

    August 6, 2022

    A new ransomware family called ‘GwisinLocker’ targets South Korean healthcare, industrial, and pharmaceutical companies with Windows and Linux encryptors, including support for encrypting VMware ESXi servers and virtual machines. The new malware is the product of a lesser-known threat actor dubbed Gwisin, which means “ghost” in Korean. The actor is of unknown origin but appears to ...

  • Roaming Mantis hits Android and iOS users in malware, phishing attacks

    July 19, 2022

    After hitting Germany, Taiwan, South Korea, Japan, the US, and the U.K. the Roaming Mantis operation moved to targeting Android and iOS users in France, likely compromising tens of thousands of devices. Roaming Mantis is believed to be a financially-motivated threat actor that started targeting European users in February. In a recently observed campaign, the threat actor ...

  • NATO Cooperative Cyber Defense Centre of Excellence (CCDCOE) held a flag-raising ceremony for Canada, the Republic of Korea and Luxembourg

    May 5, 2022

    NATO Cooperative Cyber Defense Centre of Excellence (CCDCOE) raised the flags of Canada, the Republic of Korea and Luxembourg to welcome the most recent members of CCDCOE’s multinational family. „It is a great honour to have Canada, Republic of Korea and Luxembourg in our growing and diverse family of like-minded nations. Each member of the CCDCOE ...

  • Suspected DarkHotel APT resurgence targets luxury Chinese hotels

    March 21, 2022

    A new wave of suspected activity conducted by the DarkHotel advanced persistent threat (APT) group has been disclosed by researchers. Last week, Trellix researchers Thibault Seret and John Fokker said that a malicious campaign has been targeting luxury hotels in Macao, China since November 2021, and based on clues in the attack vector and malware used, ...