Ketman describes GitHub organizations allegedly established and maintained by DPRK IT workers as hubs for credibility building, codebase management, recruitment fronts, malware-spreading opportunities, and crypto scams. The report focuses on organizations…
« Reports in 2025 »
792 reports
A July 2025 supply-chain attack against BigONE drained an estimated $27 million from the exchange, and the excerpt says the attacker later moved funds using laundering methods commonly associated with North Korean Lazarus activity. The stolen assets were …
Leaked Apache access, error, virtual-host, and configuration logs reconstruct Kimsuky/APT43 phishing infrastructure used against South Korean government and military targets in 2025. The operators staged domains including sponetcloud.com and websecurityno…
Okta Threat Intelligence found that DPRK IT-worker operations now affect remote-hiring organizations far beyond U.S. big technology companies. The investigation tracked more than 130 facilitator and worker identities tied to over 6,500 initial job intervi…
A Korean analysis attributes a Python malware file named config.py to Lazarus activity focused on cryptocurrency theft. The script is designed to collect Chrome and Chromium browser profile data, including cryptocurrency wallet extension storage, cookies,…
Sandfly Security released a detection script for a Linux Loadable Kernel Module rootkit described in a Phrack data dump attributed in the source to a threat actor purportedly from North Korea. The tool checks for hidden kernel modules that disappear from …
PIOLINK links recent APT37 activity to a shared C2 infrastructure used to operate Rustonotto, Chinotto, and FadeStealer against targets connected to North Korea policy, human rights, and South Korean interests. Initial access uses Windows shortcut files a…
The analysis reviews file listings, shell history, browser history and development artifacts from the Phrack “APT Down — The North Korea Files” leak and frames them as Kimsuky/APT43-related material. The evidence shows malware-development and intrusion to…
ESET describes DeceptiveDevelopment as a North Korea-aligned financially motivated group active since at least 2023 and tightly connected to WageMole, the activity cluster associated with North Korean IT workers. Operators pose as recruiters on platforms …
Seedify reported that a DPRK state-affiliated Web3 hacking group gained access to a developer’s private key at about 12:05 UTC and used the access to abuse minting privileges. The attacker modified OFT contract settings and minted unauthorized SFUND token…
A Korean-language analysis attributes a malicious LNK lure to suspected Kimsuky activity targeting a Korea National Defense University security policy professor. The lure impersonated the Military Affairs Office of the Chinese Embassy in South Korea and d…
WhoisXML API investigated DNS infrastructure tied to a Lazarus subgroup that used PondRAT, ThemeForestRAT, and RemotePE against financial and cryptocurrency organizations. The analysis covered 19 domain and two IP indicators from Fox-IT incident-response …
Gunra is a double-extortion ransomware operation that uses phishing, data theft, Windows and Linux encryptors, Tor leak sites, and dedicated negotiation panels. The analysis identifies Conti-related code overlap in early Windows samples, reused Ngioweb an…
Trellix uncovered a North Korean IT-worker employment fraud attempt after correlating applicant email addresses from OSINT reporting with telemetry from a major U.S. healthcare provider’s hiring process. The suspected operative used the persona “Kyle Lank…
Barracuda profiles Lazarus Group as a DPRK state-linked cybercrime and espionage ecosystem operating under the Reconnaissance General Bureau rather than a single monolithic actor. The article distinguishes major clusters including TEMP.Hermit, Kimsuky/APT…