Threat Intelligence / Actor / Suspected DPRK
Suspected DPRK
As of 2026-07-21, Suspected DPRK is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 1 threat spanning malware. Also known as Suspected DPRK (DeceptiveDevelopment / Lazarus-adjacent cluster), DeceptiveDevelopment, DEV#POPPER, Operation DreamJob adjacent.
Also known as: Suspected DPRK (DeceptiveDevelopment / Lazarus-adjacent cluster), DeceptiveDevelopment, DEV#POPPER, Operation DreamJob adjacent, Lazarus Group (suspected overlap)
Tracked threats
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →