North Korean-sponsored Lazarus hacking group has switched focus on new targets. Kaspersky security researchers observed Lazarus expanding its supply chain attack capabilities. The group used a new variant of the BLINDINGCAN backdoor to target a South Korean think tank in June after deploying it to breach a Latvian IT vendor in May. The same RAT was also deployed by Lazarus when targeting cryptocurrency exchanges and related entities in the past. Google spotted Lazarus in January while targeting security researchers in social engineering attacks using elaborate fake “security researcher” social media personas.”]

