Latest updates for Lazarus Group

Fresh curated links around Lazarus Group are collected here so marketers can spot useful updates and turn timely ideas into posts faster.

Recent items include:

  • Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms
  • Lazarus Lures Developers With Backdoored Coding Tests
  • GraphAlgo Scam: Lazarus Hackers Register Real US LLCs to Spread Malware

Post angles to try

Share the most useful takeaway for your audience.
Turn one article into a quick practical checklist.
Ask your audience how this shift affects their work.
Turn angles into scheduled posts

Fresh articles and ideas

Recent curated links from global sources. Generate one free draft from any story, then use SocialBu to schedule and refine your content calendar.

thehackernews.com /5 days ago

Lazarus Deploys RemotePE Memory-Only RAT Against Financial and Crypto Firms

Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financia...

Read source
gbhackers.com /1 month ago

Lazarus Lures Developers With Backdoored Coding Tests

North Korea-linked hackers are using AI-assisted malware and backdoored coding challenges to quietly loot millions in cryptocurrency from Web3 developers. Expel assesses with high...

Read source
hackread.com /1 month ago

GraphAlgo Scam: Lazarus Hackers Register Real US LLCs to Spread Malware

ReversingLabs has discovered a fresh wave of the graphalgo campaign in which North Korean Lazarus hackers are using fake Florida LLCs, mimicking SWFT Blockchain, and using GitHub t...

Read source
infosecurity-magazine.com /1 month ago

North Korean Blamed for $290m KelpDAO Crypto Heist

North Korea’s Lazarus Group is pegged for a $290m crypto theft at KelpDAO

Read source
crypto.news /1 month ago

North Korea’s Lazarus Group targets crypto execs with new macOS malware

North Korea’s Lazarus Group is using “Mach-O Man” macOS malware and fake meeting invites to hijack crypto execs and fund nine-figure DeFi raids. Lazarus, the North Korean state-bac...

Read source
gbhackers.com /1 month ago

Lazarus Targets macOS Users With New “Mach-O Man” Malware Kit

Lazarus Group is abusing “ClickFix” social engineering to push a new macOS malware kit dubbed “Mach-O Man,” giving attackers a direct path to credentials, Keychain secrets, and cor...

Read source
cointelegraph.com /1 month ago

Lazarus-linked macOS malware hits crypto and fintech firms

Security researchers linked a new “Mach-O Man” malware kit to a Lazarus campaign that uses fake meeting invites and ClickFix prompts to steal credentials and access corporate syste...

Read source
cryptopotato.com /1 month ago

ZachXBT Uncovers $3.5M Operation by North Korean Fake Devs Inside Crypto Firms

A hacked device uncovered how North Korean developers secretly earned millions in crypto while working across different projects.

Read source
scmp.com /1 month ago

North Korea’s Lazarus suspected of stealing US$290 million in KelpDAO cyberattack

A notorious North Korean hacking group is likely behind the theft of nearly US$300 million in cryptocurrency over the weekend, an affected party has said, in the biggest known cryp...

Read source
protos.com /1 month ago

LayerZero among bridges Lazarus using to launder loot

Lazarus launders loot like lightning, while the bridges it uses, including LayerZero, respond in very different ways. The post LayerZero among bridges Lazarus using to launder loot...

Read source
thehackernews.com /1 month ago

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea

Threat actors likely associated with the Democratic People's Republic of Korea (DPRK) have been observed using GitHub as command-and-control (C2) infrastructure in multi-stage atta...

Read source
infosecurity-magazine.com /1 month ago

North Korean Hackers Target Crypto Firms with ClickFix and AI-Made Zoom Lures

Arctic Wolf attributed this large-scale spear-phishing campaign to BlueNoroff, a financially motivated subgroup of the Lazarus Group

Read source
hackread.com /1 month ago

North Korean Hackers Abuse GitHub to Spy on South Korean Firms

Researchers from FortiGuard Labs have uncovered a high-severity spying campaign targeting South Korean companies. Discover how North Korean…

Read source
cryptobriefing.com /1 month ago

Lazarus Group linked to $292M DeFi hack, $13B TVL outflows ensue

The hack underscores the urgent need for enhanced DeFi security measures to mitigate systemic risks and prevent future large-scale exploits. The post Lazarus Group linked to $292M...

Read source
hackread.com /1 month ago

UNC1069 Targets Node.js Maintainers via Fake LinkedIn, Slack Profiles

North Korean group UNC1069 targets Node.js maintainers using fake LinkedIn and Slack profiles to spread malware and compromise open source packages.

Read source
thehackernews.com /1 month ago

China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing

A China-aligned threat actor has set its sights on European government and diplomatic organizations since mid-2025, following a two-year period of minimal targeting in the region....

Read source
thehackernews.com /2 days ago

Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels

The North Korean state-sponsored threat actor known as Kimsuky (aka Velvet Chollima) has been attributed to a fresh set of cyber attacks targeting South Korean military and corpora...

Read source
gbhackers.com /1 month ago

North Korea-Linked UNC1069 Hacks Crypto Pros via Fake Meetings

North Korea-linked threat actor UNC1069 is running a highly targeted campaign that abuses fake Zoom, Google Meet, and Microsoft Teams meetings to compromise cryptocurrency and Web3...

Read source
gbhackers.com /1 week ago

Kimsuky Uses LNK, JSE Lures to Target Recruiters, Crypto Users, Defense Officials

Kimsuky Hackers Use LNK and JSE Lures to Target Recruiters, Crypto Users, and Defense Officials. North Korea-linked threat group Kimsuky has launched at least four distinct spear-p...

Read source
gbhackers.com /1 month ago

GitHub-Backed Malware Spread via LNK Files in South Korea

Hackers are abusing Windows shortcut files and GitHub to run a stealthy, multi‑stage malware campaign against organizations in South Korea. The operation chains LNK files, PowerShe...

Read source
thehackernews.com /3 weeks ago

China-Linked UAT-8302 Targets Governments Using Shared APT Malware Across Regions

A sophisticated China-nexus advanced persistent threat (APT) group has been attributed to attacks targeting government entities in South America since at least late 2024 and govern...

Read source
thehackernews.com /2 weeks ago

Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt Strike

The Belarus-aligned threat group known as Ghostwriter has been attributed to a fresh set of attacks targeting governmental organizations in Ukraine. Active since at least 2016, Gho...

Read source
hackread.com /1 month ago

North Korean Hackers Pose as Trading Firm to Steal $285M from Drift

North Korean hackers (UNC4736) posed as a trading firm for six months to infiltrate Drift Protocol, using social engineering tactics to steal $285M without suspicion.

Read source
infosecurity-magazine.com /1 month ago

GitHub Used as Covert Channel in Multi-Stage Malware Campaign

LNK files use GitHub C2, embedded decoders and PowerShell for persistence and data exfiltration

Read source

Turn fresh research into a full content calendar

Use SocialBu to discover ideas, generate post drafts, and schedule them across your social channels.

Sources covering Lazarus Group

scmp.com

Recent coverage from public sources
Public source

cointelegraph.com

Recent coverage from public sources
Public source

crypto.news

Recent coverage from public sources
Public source

cryptobriefing.com

Recent coverage from public sources
Public source

cryptopotato.com

Recent coverage from public sources
Public source

feeds.feedburner.com

Recent coverage from public sources
Public source