Operation WizardOpium
- First seen
- 2019-11-10 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state, unknown
- Profile updated
- 2026-07-07 11:58:41
Targeted industries: technology-and-telecommunications media-and-entertainment
Context
We are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain very weak code similarities with Lazarus attacks, although these could very well be a false flag. The profile of the targeted website is more in line with earlier DarkHotel attacks that have recently deployed similar false flag attacks.
Exploited vulnerabilities
- CVE-2019-13720 (vulnerability)
Reports & references
- Kaspersky — 94866 (report)