Lazarus APT unveils fileless remote access Trojan designed to evade detection

2026-05-26T08:51:42Z7aba7d6f20aa983c8dc97522ad63005bebc90a46fe1bd53d1010089c45e05a50
CVE-2026-26980CVE-2026-9082anthropicclickfixdata-aggregationdisinformationfileless-RATghost-cmshealthcare-breachhosting-takedownios16kash-patel-sitelazarusmemory-onlyonlyfanspatching-gapproject-glasswingstark-industriesthird-party-vendorvulnerability-discoverywhatsappzero-click

What happened

Feed roundup (May 24–26, 2026): North Korea-linked Lazarus is deploying a stealthy memory-only, fileless remote-access Trojan to evade detection. A patched Ghost CMS flaw (CVE-2026-26980) is being actively exploited to push ClickFix attacks across 700+ unpatched sites, and a ClickFix-based malware campaign also impacted the FBI director’s merchandise site (used to host a fake Cloudflare page). A healthcare third-party breach at The Oncology Institute exposed patient information; a threat actor is selling a reconstructed 340 million OnlyFans-related profiles dataset built from prior leaks and公开

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
7aba7d6f20aa983c8dc97522ad63005bebc90a46fe1bd53d1010089c45e05a50
Enrichment time
2026-05-26T08:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.