He is everywhere
First seen: 2016-02 •
Last seen: 2026-06
#VHD • 2020-07
Kaspersky linked VHD ransomware operations to Lazarus after incident-response evidence found the MATA framework backdoor in the same victim environment and no sign of another actor during the intrusion. The campaign used victim-specific spreading utilities, administrative credentials, SMB brute forcing, WMI execution, VPN exploitation, Active Directory takeover, and network-wide ransomware staging, while later reporting framed VHD as part of DPRK-linked financially motivated ransomware experimentation.
6
Related Reports
1
Affected Countries
71
Months Since
He is everywhere