Lazarus APT unveils fileless remote access Trojan designed to evade detection
2026-05-26T08:51:42Z•7aba7d6f20aa983c8dc97522ad63005bebc90a46fe1bd53d1010089c45e05a50
CVE-2026-26980CVE-2026-9082anthropicclickfixdata-aggregationdisinformationfileless-RATghost-cmshealthcare-breachhosting-takedownios16kash-patel-sitelazarusmemory-onlyonlyfanspatching-gapproject-glasswingstark-industriesthird-party-vendorvulnerability-discoverywhatsappzero-click
What happened
Feed roundup (May 24–26, 2026): North Korea-linked Lazarus is deploying a stealthy memory-only, fileless remote-access Trojan to evade detection. A patched Ghost CMS flaw (CVE-2026-26980) is being actively exploited to push ClickFix attacks across 700+ unpatched sites, and a ClickFix-based malware campaign also impacted the FBI director’s merchandise site (used to host a fake Cloudflare page). A healthcare third-party breach at The Oncology Institute exposed patient information; a threat actor is selling a reconstructed 340 million OnlyFans-related profiles dataset built from prior leaks and公开
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 7aba7d6f20aa983c8dc97522ad63005bebc90a46fe1bd53d1010089c45e05a50
- Enrichment time
- 2026-05-26T08:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.