The Lazarus group, linked to North Korean actors, has been targeting IIS servers to deploy malicious ASP web shells, facilitating the spread of malware, including the LazarLoader variant. These attacks involve exploiting web server vulnerabilities and use C2 servers to maintain stealth and longevity in cyber operations. Cybersecurity firm AhnLab has recommended regular security audits, stronger authentication, up-to-date software, and constant network traffic monitoring as safeguards against such attacks.

China-linked spies backdoored authentication stack to stay hidden for years
A China-linked cyber espionage group known as Velvet Ant spent nearly a decade inside the internal network of an unnamed organization without being detected, according


