Sign in

lazarusholic

@lazarusholic.bsky.social
159 followers 111 following 1.4K posts

a big fan of lazarus. lazarus.day

PostsRepliesMedia
lazarusholic @lazarusholic.bsky.social · 1h
"How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group" published by ZachXBT. #TraderTraitor, #MoneyLaundering, #Lazarus, #Bybit, #Bitget x.com/zachxbt/status/21070816380733…
x.com
How I infiltrated a Chinese organized crime syndicate that has laundered $1B+ across multiple exploits for Lazarus Group
000
lazarusholic @lazarusholic.bsky.social · 2h
"Daily Life Inside North Korea's IT Worker Compounds" published by HaydenMckenzie. #ITWorker haydenmckenzie.com/research/Daily+L…
haydenmckenzie.com
Daily Life Inside North Korea's IT Worker Compounds
000
lazarusholic @lazarusholic.bsky.social · 02/10/2026
"How AI Helped Chainalysis Investigators Trace the $387 Million North Korea Stole from Bitget" published by Chainalysis. #MoneyLaundering, #Bitget www.chainalysis.com/blog/387m-bitge…
chainalysis.com
How AI Helped Chainalysis Investigators Trace the $387 Million North Korea Stole from Bitget
010
lazarusholic @lazarusholic.bsky.social · 01/10/2026
"PolinRider Switches to Ethereum C2 in 30+ Repositories" published by SafeDep. #GitHub, #PolinRider safedep.io/polinrider-ethereum-c2-g…
safedep.io
PolinRider Switches to Ethereum C2 in 30+ Repositories
001
lazarusholic @lazarusholic.bsky.social · 01/10/2026
"Bitget" published by Rekt. #Bitget rekt.news/bitget-rekt
rekt.news
Bitget
000
lazarusholic @lazarusholic.bsky.social · 30/09/2026
"SlowMist Investigation Progress Report: Bitget" published by Slowmist. #Bitget github.com/slowmist/Knowledge-Base/…
github.com
SlowMist Investigation Progress Report: Bitget
000
lazarusholic @lazarusholic.bsky.social · 30/09/2026
"August 2026 Threat Trend Report on APT Attacks (South Korea)" published by Ahnlab. #Kimsuky, #Phishing, #LNK, #GitHub, #AutoIt, #XenoRAT, #Hangul, #PubNub asec.ahnlab.com/en/95649
asec.ahnlab.com
August 2026 Threat Trend Report on APT Attacks (South Korea)
002
lazarusholic @lazarusholic.bsky.social · 30/09/2026
"SEAL weekly stats: Sept. 22-29, 2026" published by SecurityAlliance. #Trend, #UNC1069, #SINT69 radar.securityalliance.org/seal-wee…
radar.securityalliance.org
SEAL weekly stats: Sept. 22-29, 2026
010
lazarusholic @lazarusholic.bsky.social · 29/09/2026
"Bitget Loses USD 351.6 Million in Hot Wallet Breach in Likely North Korea Attack" published by Trmlabs. #TraderTraitor, #Bitget www.trmlabs.com/resources/blog/bitg…
trmlabs.com
Bitget Loses USD 351.6 Million in Hot Wallet Breach in Likely North Korea Attack
010
lazarusholic @lazarusholic.bsky.social · 28/09/2026
"Chinese illicit actors laundering Bitget exploit funds for alleged DPRK attackers" published by ZachXBT. #MoneyLaundering, #Bitget x.com/zachxbt/status/21045286884696…
x.com
Chinese illicit actors laundering Bitget exploit funds for alleged DPRK attackers
010
lazarusholic @lazarusholic.bsky.social · 28/09/2026
"Their GitHub Repo Was Compromised. The Trail Led to North Korea." published by tarunrd77. #GitHub, #VSCode, #PolinRider, #NullReceiver medium.com/@tarunrd77/their-github-…
medium.com
Their GitHub Repo Was Compromised. The Trail Led to North Korea.
000
lazarusholic @lazarusholic.bsky.social · 26/09/2026
"XCTDH Adopts Hash Hiding" published by RansomISAC. #OmniStealer, #NullReceiver, #HashHiding ransom-isac.org/blog/xctdh-adopts-h…
ransom-isac.org
XCTDH Adopts Hash Hiding
001
lazarusholic @lazarusholic.bsky.social · 26/09/2026
"PolinRider is A/B Testing its Way Past Your Detections" published by OpenSourceMalware. #GitHub, #VSCode, #PolinRider, #NullReceiver opensourcemalware.com/blog/polinrid…
opensourcemalware.com
PolinRider is A/B Testing its Way Past Your Detections
002
lazarusholic @lazarusholic.bsky.social · 26/09/2026
"The Women Behind North Korea's IT Worker Operations" published by HaydenMckenzie. #ITWorker haydenmckenzie.com/research/dprk-it…
haydenmckenzie.com
The Women Behind North Korea's IT Worker Operations
000
lazarusholic @lazarusholic.bsky.social · 25/09/2026
"Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026" published by Elliptic. #Bitget www.elliptic.co/insights/bitget-att…
elliptic.co
Bitget attack pushes suspected North Korea crypto heists over $1 billion in 2026
011
lazarusholic @lazarusholic.bsky.social · 25/09/2026
"Bitget Security Latest Incident Update: Fund Tracing and Recovery Bounty Program" published by Bitget. #Bitget www.bitget.com/support/articles/125…
bitget.com
Bitget Security Latest Incident Update: Fund Tracing and Recovery Bounty Program
000
lazarusholic @lazarusholic.bsky.social · 25/09/2026
"Bitget Security Incident 12-Hour Progress Update" published by GracyChen. #Bitget x.com/GracyBitget/status/2103359775…
x.com
Bitget Security Incident 12-Hour Progress Update
000
lazarusholic @lazarusholic.bsky.social · 23/09/2026
"PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager" published by Slowmist. #PolinRider slowmist.medium.com/threat-intellig…
slowmist.medium.com
PolinRider Poisons Nova, Using On-Chain Transactions as a C2 Manager
000
lazarusholic @lazarusholic.bsky.social · 23/09/2026
"Graphalgo campaign spreads to Terraform providers and Go Modules" published by Aikido. #GitHub, #Graphalgo www.aikido.dev/blog/graphalgo-terra…
aikido.dev
Graphalgo campaign spreads to Terraform providers and Go Modules
000
lazarusholic @lazarusholic.bsky.social · 23/09/2026
"SEAL weekly stats: Sept. 15-22, 2026" published by SecurityAlliance. #UNC1069, #ContagiousInterview, #SINT01 radar.securityalliance.org/seal-wee…
radar.securityalliance.org
SEAL weekly stats: Sept. 15-22, 2026
010
lazarusholic @lazarusholic.bsky.social · 22/09/2026
"Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures" published by SOCRadar. #Phishing, #Konni, #LNK, #ConflictCompass, #VelvetCake socradar.io/blog/operation-conflict…
socradar.io
Operation Conflict Compass: Konni Targets Ukraine via Malicious LNK Lures
001
lazarusholic @lazarusholic.bsky.social · 22/09/2026
"From fake interviews to malicious repositories: Disrupting Contagious Interview" published by Atlassian. #ContagiousInterview, #BeaverTail, #InvisibleFerret, #FamousChollima, #OtterCookie, #GolangGhost, #PylangGhost www.atlassian.com/blog/how-we-build…
atlassian.com
From fake interviews to malicious repositories: Disrupting Contagious Interview
000
Reposted by lazarusholic
Daniel Gordon @validhorizon.bsky.social · 19/09/2026
God I hate this so much. This is extremely not TraderTraitor. And now everyone is going to call this TraderTraitor forever.
011
lazarusholic @lazarusholic.bsky.social · 21/09/2026
"威胁情报|PolinRider 投毒 Nova,链上交易充当 C2 管理器" published by Slowmist. #PolinRider mp.weixin.qq.com/s?__biz=MzU4ODQ3NT…
mp.weixin.qq.com
威胁情报|PolinRider 投毒 Nova,链上交易充当 C2 管理器
000
lazarusholic @lazarusholic.bsky.social · 21/09/2026
"North Korea’s Hangro Revisited" published by SynapticSecurity. #OpSec, #Hangro blog.synapticsystems.de/north-korea…
blog.synapticsystems.de
North Korea’s Hangro Revisited
000
lazarusholic @lazarusholic.bsky.social · 20/09/2026
"GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign" published by CloudSEK. #GitHub, #NPM, #PolinRider, #NullReceiver, #GHAPPIER www.cloudsek.com/blog/ghappier-malw…
cloudsek.com
GHAPPIER - One loader, sixty-five repositories, twenty-two accounts: an unreported loader family beside DPRK's PolinRider campaign
001
lazarusholic @lazarusholic.bsky.social · 18/09/2026
"Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties" published by SentinelOne. #TraderTraitor, #FLATROOF, #ROOFDECK www.sentinelone.com/labs/dont-call-…
sentinelone.com
Don’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto Ties
000
lazarusholic @lazarusholic.bsky.social · 18/09/2026
“North Korean "WaterPlum," commonly referred to as “Contagious Interview,” Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe” published by JPNPA. #WaterPlum, #DPRK www.npa.go.jp/bureau/cyber/pdf/2026…
npa.go.jp
North Korean "WaterPlum," commonly referred to as “Contagious Interview,” Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe
010
lazarusholic @lazarusholic.bsky.social · 18/09/2026
"August 2026 Threat Trend Report on APT Groups" published by Ahnlab. #Trend, #DreamJob, #Kimsuky, #Lazarus, #FamousChollima, #JasperSleet, #PolinRider, #CVE202668820 asec.ahnlab.com/en/95478
asec.ahnlab.com
August 2026 Threat Trend Report on APT Groups
000
lazarusholic @lazarusholic.bsky.social · 18/09/2026
"PolinRider Spreads Through Compromised GitHub Accounts and Packagist" published by Socket. #GitHub, #EtherHiding, #VSCode, #PolinRider, #NullReceiver socket.dev/blog/polinrider-github-p…
socket.dev
PolinRider Spreads Through Compromised GitHub Accounts and Packagist
001
lazarusholic @lazarusholic.bsky.social · 17/09/2026
"The DPRK’s Use of Overseas Labour to Violate and Evade UN Sanctions" published by MSMT. #Sanctions, #ITWorker, #MoneyLaundering msmt.info/Publications/detail/MSMT%…
msmt.info
The DPRK’s Use of Overseas Labour to Violate and Evade UN Sanctions
000
lazarusholic @lazarusholic.bsky.social · 17/09/2026
"DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks" published by Chainalysis. #UNC5342, #EtherHiding www.chainalysis.com/blog/etherhidin…
chainalysis.com
DPRK and Iran are Leading a 5.2x Surge YoY in Blockchain-Assisted Cyberattacks
011
lazarusholic @lazarusholic.bsky.social · 17/09/2026
"WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials" published by OpenSourceMalware. #NPM, #WeaselBiscuit opensourcemalware.com/blog/introduc…
opensourcemalware.com
WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
010
lazarusholic @lazarusholic.bsky.social · 17/09/2026
"Silent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord Servers" published by Silentpush. #ITWorker www.silentpush.com/blog/nk-it-worker
silentpush.com
Silent Push Exposes North Korean IT Worker Recruiting Facilitators Through Discord Servers
000
lazarusholic @lazarusholic.bsky.social · 16/09/2026
"Ransomware Landscape in H1 2026: Statistics and Key Issues" published by S2W. #Andariel, #Ransomware, #Medusa, #Rook, #puNK012 medium.com/s2wblog/ransomware-lands…
medium.com
Ransomware Landscape in H1 2026: Statistics and Key Issues
000
lazarusholic @lazarusholic.bsky.social · 16/09/2026
"SEAL weekly stats: Sept. 8-14, 2026" published by SecurityAlliance. #Trend, #ContagiousInterview, #ITWorker, #SINT01 radar.securityalliance.org/seal-wee…
radar.securityalliance.org
SEAL weekly stats: Sept. 8-14, 2026
000
lazarusholic @lazarusholic.bsky.social · 14/09/2026
"Now recruiting: North Korea looks abroad for talent in its scheme to infiltrate U.S. companies" published by NBCNews. #News, #ITWorker, #MoneyLaundering www.nbcnews.com/tech/security/north…
nbcnews.com
Now recruiting: North Korea looks abroad for talent in its scheme to infiltrate U.S. companies
001
lazarusholic @lazarusholic.bsky.social · 10/09/2026
"APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析" published by Qihoo360. #APTC55, #LNK, #LOTL mp.weixin.qq.com/s/9ilhH-WUqeNCStDf…
mp.weixin.qq.com
APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析
000
lazarusholic @lazarusholic.bsky.social · 10/09/2026
"Treasury Cracks Down on Transnational Criminal Organization Behind Cyber Scam Operations Targeting Americans" published by USTreasury. #Cryptocurrency, #Sanctions, #MoneyLaundering home.treasury.gov/news/press-releas…
home.treasury.gov
Treasury Cracks Down on Transnational Criminal Organization Behind Cyber Scam Operations Targeting Americans
000
lazarusholic @lazarusholic.bsky.social · 10/09/2026
"OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals" published by Chainalysis. #Sanctions, #MoneyLaundering, #WazirX, #Bybit www.chainalysis.com/blog/ofac-sanct…
chainalysis.com
OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals
000
lazarusholic @lazarusholic.bsky.social · 10/09/2026
"Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack" published by MalBeacon. #PyPI, #OtterCandy, #PolinRider blog.deception.pro/blog/hok-dprk-po…
blog.deception.pro
Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack
000
lazarusholic @lazarusholic.bsky.social · 09/09/2026
"기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장" published by ESTSecurity. #Kimsuky, #LNK, #GitHub, #LOTL blog.alyac.co.kr/5777
blog.alyac.co.kr
기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장
001
lazarusholic @lazarusholic.bsky.social · 09/09/2026
"GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI" published by Google. #Trend, #ITWorker, #MidnightNeptune cloud.google.com/blog/topics/threat…
cloud.google.com
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
020
lazarusholic @lazarusholic.bsky.social · 09/09/2026
"SEAL weekly stats: Sept 1-8, 2026" published by SecurityAlliance. #Trend, #Phishing radar.securityalliance.org/seal-wee…
radar.securityalliance.org
SEAL weekly stats: Sept 1-8, 2026
001
lazarusholic @lazarusholic.bsky.social · 08/09/2026
"2026년 Kimsuky의 스피어피싱·지속성 전략" published by ENKI. #Kimsuky, #Phishing, #LNK, #GitHub, #Slides, #AsyncRAT www.dailysecu.com/form/html/pascon/…
dailysecu.com
2026년 Kimsuky의 스피어피싱·지속성 전략
001
lazarusholic @lazarusholic.bsky.social · 07/09/2026
"Beyond Lazarus: Organization of DPRK Cyber Capabilities" published by KudelskiSecurity. #APT38, #Andariel, #Kimsuky, #CryptoCore, #TEMPHermit, #JadeSleet, #CitrineSleet, #ITWorker, #MoonstoneSleet, #Lazarus kudelskisecurity.com/research/beyon…
kudelskisecurity.com
Beyond Lazarus: Organization of DPRK Cyber Capabilities
001
lazarusholic @lazarusholic.bsky.social · 06/09/2026
"Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve" published by Genians. #Kimsuky, #Phishing, #LNK, #GitHub, #GitPower www.genians.co.kr/en/blog/threat_in…
genians.co.kr
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
000
lazarusholic @lazarusholic.bsky.social · 05/09/2026
"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors" published by Rapid7. #APT37, #Wateringhole, #HAProxy, #curlRAT www.rapid7.com/blog/post/tr-dprk-ap…
rapid7.com
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
000
lazarusholic @lazarusholic.bsky.social · 03/09/2026
"Contagious Interview steps outside the developer workflow" published by Jamf. #macOS, #ContagiousInterview, #OtterCookie www.jamf.com/blog/contagious-interv…
jamf.com
Contagious Interview steps outside the developer workflow
031
lazarusholic @lazarusholic.bsky.social · 03/09/2026
"Malicious code executed on clone between 2026-08-29 and 2026-09-02" published by BindsNET. #VSCode, #PolinRider, #BindsNET github.com/BindsNET/bindsnet/securi…
github.com
Malicious code executed on clone between 2026-08-29 and 2026-09-02
000