September 9, 2026
- The Lazarus umbrella has been decomposed into six clusters. Kudelski Security and Sekoia map DPRK cyber capability onto TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet and Famous Chollima following a reorganization of the North Korean intelligence service two years ago, mixing espionage with crypto theft, ransomware and bank heists, and place each in the state structure (Kudelski Security).
· Threat Activity
in One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
August 12, 2026
- Lazarus revived Operation Dream Job with a new Windows zero-day, delivering malicious PDFs via fake recruiters to exploit CVE-2026-68820 — the same afd.sys bug Microsoft patched this week — alongside CVE-2025-49113. Check Point traced a chain including a new in-memory backdoor, a kernel rootkit, and webshells against defense sectors in Europe and India (Check Point Research). Separately, ANY.RUN, BCA and NorthScan stood up a fake DeFi startup ("Blue Whale LTD") and knowingly hired suspected Famous Chollima operatives to observe DPRK IT-worker infiltration from the inside (ANY.RUN).
· Threat Activity
in When the AI Is the One Finding the Zero-Days
June 17, 2026
- Contagious Interview (Famous Chollima / North Korea) continues weaponizing developer recruitment and code-review themes to deliver malware through dev tools. The Hacker News.
· Threat Activity
in Microsoft 365 Copilot 'SearchLeak' Enables One-Click Data Theft as Novo Nordisk Loses Internal AI Models to Extortionists