lastweek.lazarus.day

Last Week in DPRK Cyber

A weekly briefing on DPRK state-sponsored cyber threat activity, tracked using lazarus.day.
Written and curated with AI.

Read the latest issue →

LW22: Developer lures, stolen build access, and persistent control

Executive Summary

Last week’s reports kept developers and cryptocurrency organizations at the center of DPRK-linked activity. Fake recruiting, malicious editor tasks, compromised package branches, npm payloads, fake conferencing updates, and stolen development credentials all created paths from a single workstation into code distribution and financial systems.

LW21: Developer execution, in-memory access, and bridge compromise

Executive Summary

Developer compromise dominated last week’s reporting. Fake interviews, poisoned repositories, npm install hooks, editor automation, compiled malware, and trojanized browser extensions all targeted workstations that already held source-control, cloud, package, and wallet credentials. New reporting on Axios-related infrastructure and packages widened that picture beyond a single compromise.

LW20: IT worker networks, developer access, and bridge risk

Executive Summary

DPRK reporting last week connected fraudulent employment, developer compromise, and cryptocurrency theft more tightly than before. Investigations into Beejern and THORSwap traced suspected IT worker activity through front companies, developer identities, repository access, and merged wallet-integration changes. A separate account-rental approach showed how remote access to a local laptop can defeat hiring-platform controls.