Lazarus Group Tops Global Hack Mentions As Spear Phishing Attacks Surge
Alex Smith
6 months ago
According to a report from South Korean security firm AhnLab, state-linked hacking organizations like the North Korea-backed Lazarus Group relied heavily on spear phishing to steal funds and gather intelligence over the last 12 months. The group often posed as conference organizers, job contacts or colleagues to trick people into opening files or running commands.
Lazarus Group: Spear Phishing Turns More Realistic With AI Lures
Reports have disclosed that one unit known as Kimsuky used artificial intelligence to forge military ID images and lodge them inside a ZIP file to make messages look legitimate.
Security researchers say the fake IDs were convincing enough that recipients opened the attachments, which then ran hidden code. The incident has been traced to mid-July 2025 and appears to mark a step up in how attackers craft their lures.
The aim is simple. Get a user to trust a message, open a file, and the attacker gets a way in. That access can lead to stolen credentials, seeded malware or drained crypto wallets. The groups linked to Pyongyang have been tied to attacks on finance and defense targets, among others.
Lazarus Group Victims Asked To Execute Commands
Some campaigns did not rely only on hidden exploits. In several cases, targets were tricked into typing PowerShell commands themselves, sometimes while believing they were following official instructions.
That step lets attackers run scripts with high privileges without needing a zero-day. Security outlets have warned that this social trick is spreading and can be hard to spot.
Lazarus Group: Old File Types, New Tricks
Attackers also abused Windows shortcut files and similar formats to hide commands that run silently when a file is opened. Researchers have documented nearly 1,000 malicious .lnk samples tied to broader campaigns, showing that familiar file types remain a favorite delivery method. Those shortcuts can execute hidden arguments and pull down further payloads.
Why This Matters Now
This makes the attacks harder to stop: tailored messages, AI-forged visuals, and tricks that ask users to run code. Multi-factor authentication and software patches help, but training people to treat unusual requests with suspicion remains key. Security teams advocate basic safety nets: update, verify, and when in doubt, check with a known contact.
According to reports, Lazarus Group and Kimsuky continue to be active. Lazarus, based on AhnLab’s findings, received the most mentions in post-cybercrime analyses over the last 12 months. The group has been singled out for financially motivated hacks, while Kimsuky seems more focused on intelligence gathering and tailored deception.
Featured image from Anadolu, chart from TradingView
Related Articles
SEC’s 2026–2030 Plan Puts Crypto At The Center Of Its Regulatory Agenda
The US Securities and Exchange Commission (SEC) has again pointed to its goal of...
Bitcoin Eyeing $60,000 Support As Iran Strikes Hammer Crypto Markets
Bitcoin traders are watching $60,000 after US-listed funds tied to the coin shed...
Premier League Crypto Sponsors Under Fire In UK Regulatory Warning
The UK’s financial watchdog has raised concerns to Premier League football...
Over $7M In Crypto Scams Thwarted As Singapore Launches Second Crackdown
Over $7 million in potential losses has now been stopped across two back-to-back...