Find notable cyber news and cases, enriched with sources, timelines, and signals.

Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations

Campaign
First reported
Last updated
Happening score
H score 38
1 unique sources, 1 articles

Summary

Hide ▲

The Lazarus Group was tied to a RemotePE campaign against financial and cryptocurrency organizations, signaling a stealth-focused operation with sustained access risk. The tooling relied on memory-only execution, EDR evasion, and a low forensic footprint to reduce detection. Activity evidence spans mid-2023 to mid-2024, indicating a long-running campaign rather than a short-lived intrusion.

Related Happenings

RemotePE memory-only RAT activity by Lazarus Group targeting financial and cryptocurrency organizations

Malware Activity
First: 25.05.2026 12:32 Last: 25.05.2026 12:32 Sources 1

How related: Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations.

About this happening: The **RemotePE** malware has been tied to **Lazarus Group** activity against **financial and cryptocurrency organizations**, raising the risk of stealthy long-term access and late...

Handala multi-stage malware with Telegram C2 and exfiltration

Malware Activity
First: 24.03.2026 11:30 Last: 24.03.2026 11:30 Sources 1

About this happening: The **Handala** malware package uses a **multi-stage payload** to give operators **remote access** to infected **Windows** devices, increasing the risk of stealthy data theft. The...

Lazarus-associated Medusa extortion campaign targeting U.S. healthcare organizations

Campaign
First: 24.02.2026 13:00 Last: 24.02.2026 13:00 Sources 1

About this happening: A **Lazarus**-associated **Medusa ransomware** campaign is targeting **U.S. healthcare organizations**, raising the risk of **extortion**, **data encryption**, and operational dis...

BlueNoroff spear-phishing campaign uses typosquatted Zoom, Teams, and Calendly lures against crypto firms

Campaign
First: 11.02.2026 00:17 Last: 11.02.2026 00:17 Sources 1

About this happening: **BlueNoroff**, a **North Korea-linked Lazarus Group** subgroup, ran a **large-scale spear-phishing campaign** against **100+ cryptocurrency organizations** in **20+ countries** b...

Labyrinth Chollima split into three North Korean hacking groups

Threat Actor Meta
First: 30.01.2026 17:40 Last: 30.01.2026 17:40 Sources 1

About this happening: **Labyrinth Chollima** has been split into **three tracked North Korean groups**, reshaping how defenders map a major DPRK cyber ecosystem and its target set. **Golden Chollima**...

Timeline

  1. 25.05.2026 12:32 2 articles · 2d ago

    Lazarus Group RemotePE long-term observation campaign against financial and cryptocurrency organizations

    Initial Disclosure

    Initial access was obtained through **social engineering on Telegram** and fake **Calendly** and **Picktime** domains, leading to compromise of an employee device. The earliest loader artifact dates to **November 2023**, showing the operation had already advanced into a staged intrusion chain.

    Show sources