Fox-IT and NCC Group analyzed a Lazarus subgroup targeting financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. In a 2024 DeFi intrusion, the actor used Telegram social eng…
« Reports in 2025 »
792 reports
Kimsuky is attributed in the source to a Korean-language lure named “donation receipt.pdf.lnk,” which masquerades as a Hangul document and child-welfare donation receipt. When executed, the LNK launches hidden PowerShell, decodes embedded Base64 content, …
NK Internet examined an Arirang 182 North Korean feature phone, a rugged IP68-rated handset with a 2.4-inch display, removable battery/SIM compartment, and domestic support references such as the 999 subscription number. The device could be switched to En…
A phishing email sent to a South Korean energy-company domain delivered a RAR attachment containing a .NET executable disguised as an air cargo waybill. The executable was identified as a PureCrypter first-stage loader that contacted 158.247.250[.]251 for…
Kimsuky activity is described using a password-protected ZIP containing a PDF-themed LNK named Update Schedule_INVITATION - 250625 UNC Ambassador's Roundtable.pdf.lnk. The lure impersonated a United Nations Command ambassador roundtable invitation and was…
Seqrite links Operation HanKook Phantom to APT37, a North Korean state-backed espionage actor also known as InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, and Ricochet Chollima. The campaign used a National Intelligence Research Society newsletter d…
KuCoin links recent fake-recruiter phishing against cryptocurrency-sector personnel to Lazarus Group/APT38, with lures delivered through LinkedIn, Telegram, and X. Non-technical victims are pushed through a fake interview site that claims a missing camera…
The research identifies suspected DPRK IT worker activity across GitHub, code-sharing sites, freelancing platforms, forums, personal portfolio pages, and resume-hosting services. It frames the activity as part of North Korean remote-job fraud, with worker…
Qianxin attributes a recent ClickFix campaign to Lazarus, tracked internally as APT-Q-1, based on overlap with prior Lazarus reporting and deployment of BeaverTail and InvisibleFerret. The campaign uses fake recruiting and interview sites to persuade vict…
A Linux variant of Gunra ransomware derived from Conti reduces its effective ChaCha20 key space to only 256 possibilities by repeatedly reseeding C's `rand()` with the same second-resolution timestamp. This fills the 32-byte key and 12-byte nonce with one…
SK Shieldus reports that Gunra ransomware, first seen in April 2025, attacked a South Korean financial institution in July 2025, causing roughly four days of service disruption and alleged theft of 13.2 TB of database material. The group operates a Tor le…
OFAC sanctioned Russian national Vitaliy Sergeyevich Andreyev for allegedly facilitating payments to Chinyong Information Technology Cooperation Company, a previously sanctioned DPRK-linked organization employing North Korean IT workers in Russia and Laos…
Anthropic reports that North Korean operatives misused Claude to support fraudulent remote-employment schemes targeting US Fortune 500 technology companies. The activity involved creating convincing false identities, completing technical and coding assess…
OFAC sanctioned a DPRK-linked fraudulent IT worker network that Chainalysis connects to cryptocurrency-enabled revenue generation for North Korea's WMD and ballistic missile programs. The designation names Vitaliy Sergeyevich Andreyev, Kim Ung Sun, Shenya…
OFAC sanctioned Vitaliy Sergeyevich Andreyev, Kim Ung Sun, Shenyang Geumpungri Network Technology, and Korea Sinjin Trading Corporation for roles in a DPRK IT worker revenue scheme. The Treasury release says DPRK IT workers use fraudulent documents, stole…