Bitrefill blames North Korean Lazarus group for cyberattack

2026-03-19T19:23:32Zf2a743aface6af2fa4245492e235e902875dd6ef28cfea4a894b5e461d420653
CISAFBIactive-exploitationandroid-perseusapt28bluenoroffcisco-fmcconnectwisedata-breachgruhandalaincident-responseinterlockios-darkswordlazarusmicrosoft-intunenation-stateprivilege-escalationransomwarescreenconnectsharepointubiquiti-unifizero-dayzimbra

What happened

Multiple high-impact incidents and active exploitations were reported: Bitrefill attributes an early-March compromise to North Korea’s Lazarus/Bluenoroff group; the FBI seized Handala data-leak sites after a destructive Stryker attack that wiped ~80,000 devices (abusing Microsoft Intune), prompting CISA guidance to harden Intune. Russian APT28 (GRU) actors are exploiting a Zimbra Collaboration Suite XSS in attacks on Ukrainian government targets (CISA ordered federal patching). A critical Microsoft SharePoint flaw is being actively exploited. Interlock ransomware has been leveraging a maximum‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f2a743aface6af2fa4245492e235e902875dd6ef28cfea4a894b5e461d420653
Enrichment time
2026-03-19T19:23:32Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Bitrefill blames North Korean Lazarus group for cyberattack · Baitaphish