INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploying Kaolin RAT via Spear-Phishing

| 2026-09-01 00:00 CRITICAL HIGH MALWARE & BOTNETS PHISHING & SOCIAL ENGINEERING STATE-SPONSORED & ESPIONAGE
Executive Summary
AI-generated
A ransomware operation, attributed to the threat group GOLD SHERWOOD, was detected on September 1, 2026, originating from an external IP address in the Netherlands. The attackers used legitimate tools and compromised credentials to evade detection, deploying ransomware within 24 hours of initial access, with some incidents occurring as soon as a few hours after post-compromise activity began. The targeted sector includes various industries, with over 683 victim names added to the leak site by July 2026, including at least 169 victims in July alone. The attackers exploit vulnerabilities in firewalls and abuse VPN services credentials for initial access, often using tools such as FortiGate firewall management interfaces or compromised credentials against multiple VPN services. As of September 1, 2026, the current status is that the operation appears to be ongoing, with continued deployment of ransomware and posting of victim names on a dedicated leak site.
Technical Mitigations AI-generated
• Apply the vendor fix for CVE-2024-55591 and treat internet-facing systems that were not patched in time as potentially compromised until verified. • Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

a8ba89••••••••••••••••••••••••••••••••••
a438ba••••••••••••••••••••••••••••••••••
be8c52••••••••••••••••••••••••••••••••••
c96baa••••••••••••••••••••••••••••••••••
0be8f4••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ddba5b••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
a348f5••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
ccdde8••••••••••••••••••••••••••••••••••••••••••••••••••••••••••
no•••••.sys
xk•••••.sys
g1•••••.sys
re•••••.bat
hw•••••.exe
de•••••.exe
RE•••••.txt
bi•••••.exe
bc4a8d••••••••••••••••••••••••••
07e9f0••••••••••••••••••••••••••
738df7••••••••••••••••••••••••••
b23b65••••••••••••••••••••••••••
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
HavocHavoc CVE-2024-55591CVE-2024-55591
Target & Sectors
Global Scope
Incident Timeline
‎September 2025
Threat actors posted fewer than 20 victim names each month in September 2025, with the average increasing to over 75 by January 2026.
victims 20 victim names
victims 683 victim names
‎June 2026
Threat actors used PowerShell to enforce monitoring exclusions for Windows Defender, allowing them to deploy ransomware locally on single hosts or network shares.
infrastructure Windows
infrastructure Linux
‎July 2026
Threat actors used Rclone to exfiltrate data from compromised systems, often limiting its scope and leveraging legitimate credentials for lateral movement.
infrastructure Windows
infrastructure Fortigate
‎2026/09/01
Threat actors used a Netlogon-hosted script to ensure consistent execution across multiple hosts, while also disabling AV and EDR solutions.
infrastructure Windows
Tactical Metrics
Metrics
infrastructure
‎Fortigate
Affected Product
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
‎Linux
Affected Product
Metrics
victims
20
Victim Names
Metrics
victims
683
Victim Names
Intelligence Sources