lastweek.lazarus.day

Last Week in DPRK Cyber

A weekly briefing on DPRK state-sponsored cyber threat activity, tracked using lazarus.day.
Written and curated with AI.

Read the latest issue →

LW38: Compromised developers, blockchain dead drops, and worker facilitators

Executive Summary

Last week’s reporting traced several DPRK operations through developer accounts, source repositories, package registries, and fake recruitment. The GHAPPIER investigation found one loader across at least 65 repositories and 22 accounts, including a malicious npm release built by a legitimate GitHub Actions workflow. Separate research found PolinRider in Packagist development versions, while a joint government advisory said WaterPlum had infected at least 30,000 devices in more than 100 countries.

LW37: Kimsuky persistence, interactive supply-chain access, and adversarial AI

Executive Summary

Last week’s reporting followed Kimsuky across malicious shortcuts, a trojanized installer, fake meeting pages, and legitimate remote-access tools. The delivery methods varied, but the campaigns repeatedly used scheduled execution and trusted internet services to keep access alive and divide command, collection, and exfiltration traffic.

LW36: Transitive npm malware, AI-made lures, and Linux implants

Executive Summary

Last week’s reporting documented several ways attackers turned familiar software and services into execution paths. A malicious npm package sat three dependencies below the package a developer chose to install. A forged BindsNET merge commit ran JavaScript when affected clones opened in VS Code-compatible editors, while trojanized macOS installers delivered OtterCookie outside the usual fake coding-test workflow.

LW35: Persistent npm compromise, remote-worker hardware, and LNK phishing

Executive Summary

Last week’s reporting returned to two recurring routes into trusted environments: compromised developer accounts and fraudulent remote employment. PolinRider operators retained control of a legitimate developer’s GitHub identity, infected all seven of his active repositories, and published new malicious versions after an earlier npm takedown. Huntress, meanwhile, documented suspected DPRK workers using altered identity records, location-masking services, and hardware that provided remote control and redirected audio or video.

LW34: Rust build compromise, remote-control phishing, and hiring fraud

Executive Summary

Last week’s reporting followed attacks on developers, email users, and remote hiring pipelines. A fake coding challenge delivered a new JavaScript implant to a cryptocurrency developer. A separate Rust supply-chain incident caused malware to run when affected projects compiled, with infrastructure overlaps that researchers tied to earlier DPRK campaigns without reaching a conclusive attribution for the crate compromise.

LW33: Dream Job zero-day, blockchain C2, and remote worker access

Executive Summary

Last week’s reporting covered two distinct routes into trusted environments. Lazarus used recruitment lures and trojanized PDF software against defense, aerospace, and aviation organizations, then exploited a Windows zero-day to run its FudModule rootkit. A separate package campaign hid malicious loaders in six npm packages and recovered changing command infrastructure from Ethereum transactions.

LW32: AI adoption, developer compromise, and IT worker exposure

Executive Summary

Last week’s reporting covered DPRK activity against developers, software supply chains, and remote hiring. Genians found Kimsuky infrastructure running local AI tools and document retrieval software. CrowdStrike attributed the poisoning of 131 AI framework packages to STARDUST CHOLLIMA, while an investigation into North Korean command-and-control servers found evidence of intrusions at hundreds of organizations.

LW31: Package compromise, watering holes, and developer-led theft

Executive Summary

Last week’s DPRK-related reporting focused on open-source compromise, blockchain-based command delivery, and attacks through trusted South Korean websites and security software. Supply-chain campaigns first compromised developers or maintainers, then pushed malicious code into legitimate npm packages and Go modules. Separate research documented APT37’s NarwhalRAT infrastructure and an AFX bridge theft attributed in a detailed post-mortem to UNC4899 / TraderTraitor.

LW29: Developer access, package spread, and IT worker infrastructure

Executive Summary

Last week’s reporting joined two risks that often begin with developer access. Fake coding tests delivered cross-platform credential theft, while stolen developer accounts and package publishing access spread malicious code through GitHub and npm. PolinRider’s confirmed footprint rose to 4,367 repositories, and separate research connected the ChainVeil and ViteVenom package clusters to the same campaign with differing attribution confidence.