INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lazarus Group Deploys Kaolin RAT via Spear-Phishing Attacks Worldwide

| 2026-04-15 14:00 HIGH LOW DATA BREACH
Executive Summary
AI-generated
The German Cyber Criminal Überfall has resulted in a 92% growth in data leaks, tripling the European average for 2025 and reflecting a more volatile threat landscape. Non-English-speaking nations remain primary targets for global extortion groups, with established brands like LockBit being disrupted by agile data leak sites such as SafePay and Qilin. These groups are hitting Germany in lockstep with their global expansion, targeting high-volume environments like the Mittelstand and German professional services. The disruption has rebalanced the ecosystem into a crowded field of ransomware operations, which have been observed since 2022 and 2023, with the current surge being particularly notable for its impact on Germany, where data leaks are now at an unprecedented level, exceeding the European average by this margin.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
QilinQilin
Target & Sectors
DACH DACH