Unknown
Operation WizardOpium
misp-galaxyrefreshed 2026-09-15
sigil
Analyst brief
We are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain very weak code similarities with Lazarus attacks, although these could very well be a false flag. The profile of the targeted website is more in line with earlier DarkHotel attacks that have recently deployed similar false flag attacks.
Early access
Track Operation WizardOpium on the wire.
Early access opens the actor API and MCP server first — and an alert every time this adversary lands on the wire. One email when it's ready.
bot-protected