MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Font ResizerAa
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Reading: Kimsuky and Lazarus Join Forces in Coordinated Attacks – Cyberwarzone
Share
Font ResizerAa
MarketAlert – Real-Time Market & Crypto News, Analysis & AlertsMarketAlert – Real-Time Market & Crypto News, Analysis & Alerts
Search
  • Crypto News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFTs
    • Press Releases
    • Latest News
  • Blockchain Technology
    • Blockchain Developments
    • Blockchain Security
    • Layer 2 Solutions
    • Smart Contracts
  • Interviews
    • Crypto Investor Interviews
    • Developer Interviews
    • Founder Interviews
    • Industry Leader Insights
  • Regulations & Policies
    • Country-Specific Regulations
    • Crypto Taxation
    • Global Regulations
    • Government Policies
  • Learn
    • Crypto for Beginners
    • DeFi Guides
    • NFT Guides
    • Staking Guides
    • Trading Strategies
  • Research & Analysis
    • Blockchain Research
    • Coin Research
    • DeFi Research
    • Market Analysis
    • Regulation Reports
Have an existing account? Sign In
Follow US
© Market Alert News. All Rights Reserved.
  • bitcoinBitcoin(BTC)$78,288.003.28%
  • ethereumEthereum(ETH)$2,384.412.93%
  • tetherTether(USDT)$1.000.01%
  • rippleXRP(XRP)$1.430.52%
  • binancecoinBNB(BNB)$638.221.25%
  • usd-coinUSDC(USDC)$1.00-0.01%
  • solanaSolana(SOL)$86.981.60%
  • tronTRON(TRX)$0.329880-1.02%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.18%
  • dogecoinDogecoin(DOGE)$0.0960361.43%
Blockchain

Kimsuky and Lazarus Join Forces in Coordinated Attacks – Cyberwarzone

Last updated: November 22, 2025 6:35 am
Published: 5 months ago
Share

North Korean hacking groups Kimsuky and Lazarus have combined efforts in a coordinated attack campaign targeting critical sectors worldwide. This collaboration signifies a major shift in state-sponsored threat operations, evolving from isolated attacks to integrated campaigns focused on stealing sensitive intelligence and cryptocurrencies.

The campaign begins with Kimsuky conducting reconnaissance. The group crafts phishing emails disguised as academic conference invitations or research collaboration requests. These messages deliver malicious attachments in HWP or MSC formats. When recipients open these attachments, the FPSpy backdoor deploys. Once installed, FPSpy activates KLogEXE, a keylogger that captures passwords, email content, and system information. This initial phase maps the target’s network architecture and identifies valuable assets.

Kimsuky then transfers control to the Lazarus group. Lazarus exploits zero-day vulnerabilities to gain deeper access into compromised systems. The group weaponized CVE-2024-38193, a Windows privilege escalation flaw, to deploy malicious Node.js packages that appear legitimate. When executed, these packages provide attackers with SYSTEM-level privileges. Lazarus then installs the InvisibleFerret backdoor, which uses the Fudmodule malware component to bypass endpoint detection tools. CN-SEC security researchers noted Lazarus’s use of these sophisticated tactics.

The InvisibleFerret backdoor exhibits advanced evasion capabilities. It disguises its network traffic as normal HTTPS web requests, making detection via traffic analysis challenging for security teams. The malware specifically targets blockchain wallets, scanning system memory for private keys and transaction data stored in browser extensions and desktop applications. Attackers, in one documented instance, transferred $32 million in cryptocurrency within 48 hours without triggering security alerts.

The backdoor communicates with command and control (C2) servers through encrypted channels. These channels rotate daily, employing a domain polling strategy. Each C2 domain is disguised as a legitimate e-commerce or news website to evade suspicion.

After completing their objectives, both Kimsuky and Lazarus coordinate to erase all traces of their activity. They overwrite malicious files with legitimate system processes and thoroughly clear their digital footprints through shared infrastructure. Organizations across the defense, finance, energy, and blockchain sectors face the highest risk from this coordinated threat.

Read more on cyberwarzone.com

This news is powered by cyberwarzone.com cyberwarzone.com

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook

Like this:

Like Loading...

Related

Flow Network Addresses $3.9 Million Exploit; User Balances Secure
How AI And Big Data Are Pushing The Next Wave Of Sustainable Innovation
Fragmentation siphons up to $1.3B annually from tokenized assets, report finds
Unlocking the Future: 2025 Circular Fashion Market Outlook and Growth Forecast Through 2034
Institutional Investors Accumulate Solana Amid Retail Caution

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Email Copy Link Print
Previous Article Grayscale Launches First DOGE and XRP Spot ETFs on NYSE Arca – TokenPost
Next Article Sheye Banks champions tech-driven creative hub
© Market Alert News. All Rights Reserved.
Welcome Back!

Sign in to your account

Username or Email Address
Password

Prove your humanity


Lost your password?

%d