« Reports in 2026

553 reports

2026-09-09 • Security Alliance

SEAL handled 48 incidents from September 1–8, including DPRK intrusion losses totaling $400,000. It identified nine domains as infrastructure related to confirmed DPRK activity, several of which impersonated Microsoft Teams or Whereby services. The weekly…

#Trend #Phishing
2026-09-06 • Genians

Genians attributes 13 malicious LNK variants collected in August 2026 to Kimsuky’s Operation GitPower, citing matching LNK fingerprints, a shared custom decoder, GitHub PAT-authenticated delivery, and disguised scheduled tasks. The variants execute obfusc…

#Kimsuky #Phishing #LNK #GitHub #T1140 #T1041 #T1497 #T1027 #T1204.002 #T1566.001 #T1053.005 #T1059.001 #T1036.005 #T1102 #T1202 #T1070.003 #GitPower
2026-09-06 • Genians

Genians attributes 13 malicious LNK variants collected in August 2026 to Kimsuky’s Operation GitPower, citing matching LNK fingerprints, a shared custom decoder, GitHub PAT-authenticated delivery, and disguised scheduled tasks. The variants execute obfusc…

#Kimsuky #Phishing #LNK #GitHub #T1140 #T1041 #T1497 #T1027 #T1204.002 #T1566.001 #T1053.005 #T1059.001 #T1036.005 #T1102 #T1202 #T1070.003 #GitPower
2026-09-04 • Rapid7

Rapid7 identified a previously undocumented Linux espionage toolkit targeting South Korean media and automotive organizations and attributed the activity with medium confidence to DPRK APT operators. The framework combines a modified HAProxy implant calle…

#APT37 #Wateringhole #Lazarus #T1082 #T1119 #T1041 #T1560 #T1071.001 #T1059.004 #T1027 #T1057 #T1036.005 #T1132.001 #T1102 #T1497.001 #T1480 #T1543 #T1070.002 #T1548 #T1556.003 #T1190 #T1070.006 #T1106 #T1568 #T1572 #T1185 #T1562.006 #HAProxy #curlRAT #Ted