INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Spear-Phishing to Steal Identity Verification Credentials

| 2026-08-25 14:01 CRITICAL LOW PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
In late July 2026, North Korean IT workers impersonated foreign nationals to secure employment in technology companies, targeting the US Department of State and its allies including Japan, Canada, and the UK. The attackers typically target technology companies, with a focus on falsifying identity documents such as images supplied by a third party based in another country to register accounts. This tactic exploits legitimate processes during account creation and recovery, putting pressure on organizations to secure both login credentials and these processes. Attackers use social engineering tactics like impersonating employees to reset passwords, which can gift access to an account, similar to the 2025 M&S ransomware breach that resulted in a $400 million loss. The security question remains how confidently organizations can verify the identity of individuals making requests for password resets or lost access to their accounts.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures. • Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate. • Threat Intelligence Program (ATT&CK mitigation for Impersonation): Threat intelligence helps defenders and users be aware of and defend against common lures and active campaigns that have been used for impersonation. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
DPRK DPRK NORTH_AMERICA NORTH_AMERICA technologytechnology
Incident Timeline
‎July 2026
Threat actor groups like Scattered Spider use social engineering tactics to impersonate employees and gain access to accounts, often assisted by North Korean remote workers who fabricate identity evidence.
threat_actor Scattered Spider
financial 2025 ransomware breach
Tactical Metrics
Metrics
financial
2,025
Ransomware Breach
Intelligence Sources