Threat Intelligence / Actor / Suspected DPRK (DeceptiveDevelopment / Lazarus-adjacent cluster)
Suspected DPRK (DeceptiveDevelopment / Lazarus-adjacent cluster)
Also known as: DeceptiveDevelopment, DEV#POPPER, Operation DreamJob adjacent, Lazarus Group (suspected overlap)
Tracked threats
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →