The North Korean hacking group Lazarus is exploiting the Log4Shell vulnerability to deploy three new malware families named NineRAT, DLRAT, and BottomLoader. These malware are written in the D programming language, which is rarely used in cybercrime, helping them evade detection. This new campaign, dubbed “Operation Blacksmith”, targets manufacturing, agricultural, and physical security companies worldwide, marking a significant shift in Lazarus’ tactics and tools.

Aisuru Botnet Shifts from DDoS to Residential Proxies
Aisuru, the botnet responsible for a series of record-smashing distributed denial-of-service (DDoS) attacks this year, recently was overhauled to support a more low-key, lucrative and

