Threat Intelligence / Actor / Suspected DPRK

Suspected DPRK

As of 2026-07-21, Suspected DPRK is a North Korea-nexus threat actor tracked by Threadlinqs Intelligence across 1 threat spanning malware. Also known as Suspected DPRK (DeceptiveDevelopment / Lazarus-adjacent cluster), DeceptiveDevelopment, DEV#POPPER, Operation DreamJob adjacent.

Nation: North Korea · 1 tracked threat(s) · Categories: MALWARE

Also known as: Suspected DPRK (DeceptiveDevelopment / Lazarus-adjacent cluster), DeceptiveDevelopment, DEV#POPPER, Operation DreamJob adjacent, Lazarus Group (suspected overlap)

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence