ResearchDPRK’s Playbook: Kimsuky’s HttpTroy and Lazarus’s New BLINDINGCAN Variant
Technical walkthroughs of two DPRK intrusions: Kimsuky’s invoice-themed dropper to HttpTroy, and Lazarus’s Comebacker to BLINDINGCAN plus IOCs, TTPs, and mitigation steps
Alexandru-Cristian BardașOctober 30, 2025 • 20 min read