Bitrefill blames North Korean Lazarus group for cyberattack
2026-03-19T19:23:32Z•f2a743aface6af2fa4245492e235e902875dd6ef28cfea4a894b5e461d420653
CISAFBIactive-exploitationandroid-perseusapt28bluenoroffcisco-fmcconnectwisedata-breachgruhandalaincident-responseinterlockios-darkswordlazarusmicrosoft-intunenation-stateprivilege-escalationransomwarescreenconnectsharepointubiquiti-unifizero-dayzimbra
What happened
Multiple high-impact incidents and active exploitations were reported: Bitrefill attributes an early-March compromise to North Korea’s Lazarus/Bluenoroff group; the FBI seized Handala data-leak sites after a destructive Stryker attack that wiped ~80,000 devices (abusing Microsoft Intune), prompting CISA guidance to harden Intune. Russian APT28 (GRU) actors are exploiting a Zimbra Collaboration Suite XSS in attacks on Ukrainian government targets (CISA ordered federal patching). A critical Microsoft SharePoint flaw is being actively exploited. Interlock ransomware has been leveraging a maximum‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- f2a743aface6af2fa4245492e235e902875dd6ef28cfea4a894b5e461d420653
- Enrichment time
- 2026-03-19T19:23:32Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.