/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Cisco Talos: the Lazarus group exploited the Log4j flaw in VMware Horizon servers of energy providers in the US, Canada, and Japan from February to July 2022

Security researchers have linked a new cyber espionage campaign targeting U.S., Canadian and Japanese energy providers …

TechCrunch Carly Page

Context & Ripple Effects

The campaign sits in the longer Log4j exploitation wave: Cisco Talos and Cloudflare had already recorded attacks on the vulnerability before mass exploitation, while Microsoft and Mandiant tied its use to multiple state-linked groups. Lazarus’s use against energy-sector VMware Horizon deployments shows how a widely exposed software flaw became a route into critical-service operators.

Later Talos reporting on Lazarus targeting internet backbone and health-care organizations extends the same pattern beyond energy: the group’s focus is on sectors whose disruption or intelligence value reaches well beyond an individual victim.

First-order effects

  • Energy providers in the U.S., Canada, and Japan must treat VMware Horizon systems exposed during the reported period as potential espionage entry points and review their Log4j remediation and investigation records.
  • Cisco Talos’s attribution gives defenders a Lazarus-specific basis for prioritizing threat hunting around the affected server estate rather than treating Log4j solely as indiscriminate exploitation.

Second-order effects

  • VMware Horizon customers in other critical sectors face added pressure to verify whether their Log4j controls account for state-backed persistence, not just initial vulnerability scanning.
  • Security teams and incident-response suppliers gain a clearer case for linking vulnerability management of internet-facing enterprise software to sector-specific intelligence on Lazarus.

Third-order effects

  • Repeated Lazarus activity against energy, backbone, and health-care targets points to critical infrastructure becoming a sustained intelligence collection surface for state-linked operators.
  • If this targeting pattern persists, operators of essential services will increasingly need to prioritize remediation by adversary interest and operational importance, rather than by vulnerability severity alone.

The trend: State-linked groups are turning broadly deployed enterprise-software flaws into durable access paths for intelligence collection against critical infrastructure.

Discussion

  • @talossecurity @talossecurity on x
    Continuing on our reporting on the #LazarusGroup, we also have new research out today on how this threat actor is using three different RATs to target users in the U.S., Canada and Japan https://blog.talosintelligence.com/ ... https://twitter.com/...