« Reports in 2025 »

792 reports

2025-10-01 • Ketman

Ketman describes GitHub organizations allegedly established and maintained by DPRK IT workers as hubs for credibility building, codebase management, recruitment fronts, malware-spreading opportunities, and crypto scams. The report focuses on organizations…

#ITWorker
2025-09-30 • Okta

Okta Threat Intelligence found that DPRK IT-worker operations now affect remote-hiring organizations far beyond U.S. big technology companies. The investigation tracked more than 130 facilitator and worker identities tied to over 6,500 initial job intervi…

#ITWorker
2025-09-28 • Sandfly Security

Sandfly Security released a detection script for a Linux Loadable Kernel Module rootkit described in a Phrack data dump attributed in the source to a threat actor purportedly from North Korea. The tool checks for hidden kernel modules that disappear from …

#Kimsuky #APTDown
2025-09-26 • Piolink

PIOLINK links recent APT37 activity to a shared C2 infrastructure used to operate Rustonotto, Chinotto, and FadeStealer against targets connected to North Korea policy, human rights, and South Korean interests. Initial access uses Windows shortcut files a…

#APT37 #LNK
2025-09-25 • ESET

ESET describes DeceptiveDevelopment as a North Korea-aligned financially motivated group active since at least 2023 and tightly connected to WageMole, the activity cluster associated with North Korean IT workers. Operators pose as recruiters on platforms …

#BeaverTail #InvisibleFerret #ClickFix #DeceptiveDevelopment #Tropidoor #Tsunami #T1071.001 #T1497 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.001 #T1059 #T1585.001 #T1105 #T1055 #T1078 #T1589 #T1586
2025-09-23 • Barracuda

Barracuda profiles Lazarus Group as a DPRK state-linked cybercrime and espionage ecosystem operating under the Reconnaissance General Bureau rather than a single monolithic actor. The article distinguishes major clusters including TEMP.Hermit, Kimsuky/APT…

#Lazarus