Qihoo 360 attributes a multi-stage infection chain to Kimsuky (APT-C-55), beginning with a trojanized OrionQuests installer that drops a malicious LNK file. The LNK decrypts PowerShell that checks for analysis tools and virtual machines, profiles the host…
« Reports in 2026
553 reports
The U.S. Treasury reported that North Korean hackers used Xinbi Guarantee, an illicit marketplace that supplied escrow and transactional services to scam operators, money-laundering networks, and cybercrime syndicates. OFAC sanctioned Xinbi Guarantee and …
Chainalysis found that DPRK-linked actors laundered tens of millions of dollars stolen in the Bybit and WazirX hacks through Xinbi Guarantee's vendor network. Specialized “Black U” vendors substituted traceable stolen assets for less-tainted stablecoins s…
A live operator compromised an instrumented decoy workstation through a trojanized PyPI package and fake coding assignment, producing activity assessed as consistent with the DPRK-linked PolinRider campaign. The operator deployed JavaScript and Python pay…
ESTsecurity attributes a new malicious LNK operation targeting South Korean organizations to Kimsuky based on the group's established shortcut-based delivery and Korean business-document lures. The chain uses batch scripts, renamed Windows utilities, and …
SEAL handled 48 incidents from September 1–8, including DPRK intrusion losses totaling $400,000. It identified nine domains as infrastructure related to confirmed DPRK activity, several of which impersonated Microsoft Teams or Whereby services. The weekly…
GTIG observed at least one DPRK IT worker cluster registering LLM APIs in bulk through hijacked accounts to scale its operations. DPRK-linked clusters also used LLM prompts to profile aerospace and defense targets and generate fabricated resumes, job desc…
Kimsuky continues to target South Korean military, government, and public-sector organizations with tailored spearphishing designed for long-term espionage access. Its delivery methods include malicious LNK files disguised as documents, counterfeit softwa…
Kudelski Security and Sekoia map North Korea's offensive cyber capabilities as a distributed state system led principally by the GRIB and NIA, with frequently reorganized units conducting espionage, sabotage, ransomware, and financial theft. They divide t…
Genians attributes 13 malicious LNK variants collected in August 2026 to Kimsuky’s Operation GitPower, citing matching LNK fingerprints, a shared custom decoder, GitHub PAT-authenticated delivery, and disguised scheduled tasks. The variants execute obfusc…
Genians attributes 13 malicious LNK variants collected in August 2026 to Kimsuky’s Operation GitPower, citing matching LNK fingerprints, a shared custom decoder, GitHub PAT-authenticated delivery, and disguised scheduled tasks. The variants execute obfusc…
Rapid7 identified a previously undocumented Linux espionage toolkit targeting South Korean media and automotive organizations and attributed the activity with medium confidence to DPRK APT operators. The framework combines a modified HAProxy implant calle…
Jamf identified 14 trojanized macOS DMG and PKG samples tied to the DPRK-attributed Contagious Interview campaign, extending its delivery methods beyond fake coding tests, Visual Studio Code task files, and Git hooks. The unsigned installers launched legi…
An attacker using a BindsNET collaborator's credentials hid a malicious Visual Studio Code folder-open task inside a forged merge commit and force-pushed it across 20 branches. A routine Dependabot merge later carried the injected files into the master br…
Attackers used compromised collaborator credentials to force-push a forged merge commit across 20 BindsNET branches, eventually introducing it into `master` through a routine Dependabot merge. A hidden Visual Studio Code task automatically ran obfuscated …