Cisco Talos: the Lazarus group exploited the Log4j flaw in VMware Horizon servers of energy providers in the US, Canada, and Japan from February to July 2022
Security researchers have linked a new cyber espionage campaign targeting U.S., Canadian and Japanese energy providers …
Context & Ripple Effects
The campaign sits in the longer Log4j exploitation wave: Cisco Talos and Cloudflare had already recorded attacks on the vulnerability before mass exploitation, while Microsoft and Mandiant tied its use to multiple state-linked groups. Lazarus’s use against energy-sector VMware Horizon deployments shows how a widely exposed software flaw became a route into critical-service operators.
Later Talos reporting on Lazarus targeting internet backbone and health-care organizations extends the same pattern beyond energy: the group’s focus is on sectors whose disruption or intelligence value reaches well beyond an individual victim.
First-order effects
- Energy providers in the U.S., Canada, and Japan must treat VMware Horizon systems exposed during the reported period as potential espionage entry points and review their Log4j remediation and investigation records.
- Cisco Talos’s attribution gives defenders a Lazarus-specific basis for prioritizing threat hunting around the affected server estate rather than treating Log4j solely as indiscriminate exploitation.
Second-order effects
- VMware Horizon customers in other critical sectors face added pressure to verify whether their Log4j controls account for state-backed persistence, not just initial vulnerability scanning.
- Security teams and incident-response suppliers gain a clearer case for linking vulnerability management of internet-facing enterprise software to sector-specific intelligence on Lazarus.
Third-order effects
- Repeated Lazarus activity against energy, backbone, and health-care targets points to critical infrastructure becoming a sustained intelligence collection surface for state-linked operators.
- If this targeting pattern persists, operators of essential services will increasingly need to prioritize remediation by adversary interest and operational importance, rather than by vulnerability severity alone.
The trend: State-linked groups are turning broadly deployed enterprise-software flaws into durable access paths for intelligence collection against critical infrastructure.