Skip to content
skopnix
← adversaries
Unknown

Operation WizardOpium

misp-galaxyrefreshed 2026-09-15

sigil

Analyst brief

We are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain very weak code similarities with Lazarus attacks, although these could very well be a false flag. The profile of the targeted website is more in line with earlier DarkHotel attacks that have recently deployed similar false flag attacks.

Take it with you
References
Early access

Track Operation WizardOpium on the wire.

Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.

bot-protected