/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Cisco Talos: North Korea's Lazarus is using a new malware variant to target internet backbone infrastructure and healthcare entities in Europe and the US

A notorious hacking group working on behalf of the North Korean government is using a new strain of malware to attack healthcare entities …

The Record Jonathan Greig

Context & Ripple Effects

This report extends a long-running Lazarus record: the group was previously linked to the WannaCry ransomware campaign and later associated with the FALLCHILL remote-access tool. The notable change is the pairing of healthcare targets with infrastructure that underpins connectivity.

Healthcare had already been singled out in a joint warning on Maui ransomware, while later coverage describes Lazarus pursuing supply-chain access through authentication software. Together, the coverage shows repeated shifts in tooling and access paths rather than a one-off campaign.

First-order effects

  • Internet backbone operators and healthcare organizations in Europe and the US need to assess exposure to the newly reported malware variant and update detection and incident-response workflows.
  • Cisco Talos' findings give defenders a concrete indicator set around a campaign aimed at two operationally sensitive target classes.

Second-order effects

  • Security teams serving hospitals and network operators will face pressure to prioritize threat hunting and segmentation around externally exposed and high-availability systems.
  • The overlap between connectivity infrastructure and healthcare raises the operational stakes: a successful intrusion at either layer can force more cautious monitoring and access-control decisions across dependent organizations.

Third-order effects

  • If Lazarus continues to rotate malware and entry points across critical sectors, resilience will depend less on blocking a single tool and more on sustained detection, recovery, and cross-sector threat sharing.
  • The pattern reinforces a broader shift in which state-linked groups treat essential civilian services and enabling infrastructure as recurring targets, making targeted cyber defense an enduring operational requirement.

The trend: This is one data point in the continuing adaptation of state-linked cyber campaigns toward high-consequence civilian infrastructure through changing malware and access techniques.

Discussion

  • @talossecurity @talossecurity on x
    #NorthKorea's Lazarus Group is back again, this time with two new remote access trojans. The attacker continues to use the same infrastructure, but is changing up their eventual payloads. More here: https://blog.talosintelligence.com/ ...
  • @talossecurity @talossecurity on x
    Lazarus Group appears to be changing its tactics, increasingly relying on open-source tools and frameworks in the initial access phase of their attacks. We have a separate post up this morning on how that led us to the discovery of new #malware https://blog.talosintelligence.com/…