Lazarus Group Expands Malware Arsenal With PondRAT, ThemeForestRAT, and RemotePE
Tuesday, September 2, 2025 4:39 PM | The Hacker News
The North Korea-linked threat actor known as the Lazarus Group has been attributed to a social engineering campaign that distributes three different pieces of cross-platform malware called PondRAT, ThemeForestRAT, and RemotePE.
The attack, observed by NCC Group's Fox-IT in 2024, targeted an organization in the decentralized finance (DeFi) sector, ultimately leading to the compromise of an