Japan, the United States, and South Korea warned that North Korean IT workers are continuing to earn overseas revenue for DPRK weapons programs while expanding malicious cyber activity. The statement says these workers hide their identities and locations …
« Reports in 2025 »
792 reports
78ResearchLab analyzed Gunra ransomware in connection with the July 2025 SGI Seoul Guarantee incident and describes it as Conti-derived ransomware that commonly reaches victim servers through VPN, SSH, and RDP brute force or vulnerabilities. The sample dy…
PIOLINK describes Gunra ransomware expanding from Windows systems to Linux variants after activity first appeared in April 2025, suggesting the operators are broadening their target platforms. Reported activity has affected organizations in Taiwan, the Un…
GolangGhost is presented as a cross-platform remote access trojan associated with North Korea's Lazarus-linked Famous Chollima activity against cryptocurrency and blockchain job seekers. The infection chain uses fake recruitment sites and bogus video inte…
AppleJeus is identified as a North Korean state-sponsored group attributed to the Reconnaissance General Bureau and associated with the broader Lazarus Group umbrella. The entry says the group focuses on generating and laundering revenue for the DPRK gove…
Chollima Group links the DeTankZone/Moonstone Sleet ecosystem to a broader cluster of DPRK IT workers it calls BABYLONGROUP, centered on web3 and blockchain development. The investigation says the supposedly legitimate predecessor DefiTankLand was likely …
The YouTube transcript describes OSINT researchers discussing North Korean compromises of South Korean government and media servers, with VPN weaknesses presented as a common intrusion cause. The discussion ties the activity to Kimsuky tradecraft, includi…
A leaked operational dump attributed in the source to North Korea’s Kimsuky exposed virtual machine images, VPS data, phishing kits, rootkits, credentials, browser history, and operator infrastructure. The material shows phishing activity against South Ko…
AhnLab’s July 2025 APT trend report highlights multiple North Korea-linked intrusion patterns, including Kimsuky ClickFix activity against South Korean diplomacy, security, international politics, defense, portal, research, and expert targets. The Kimsuky…
S2W TALON analyzed leaked material distributed with Phrack’s “APT Down: The North Korea Files” and found evidence of operations against Korean government entities and domestic companies, including webmail-related source code, Ministry of Foreign Affairs-r…
Korea University's Graduate School of Information Security announced a technical briefing on material from Phrack's “APT Down: The North Korea Files,” which was said to be based on files taken from a workstation used by a suspected Kimsuky operator. The s…
Elliptic describes the February 2025 Bybit exploit as a North Korean act in which about $1.46 billion in ETH and ERC-20 tokens were transferred to an attacker-controlled address. Six months later, laundering had moved more than $1 billion through rapid mu…
A Korean-language analysis attributes a malicious LNK lure to APT37/Reaper and identifies RokRAT delivery through a decoy about an academy for successful resettlement of North Korean defectors in South Korea. The shortcut searches for PowerShell, locates …
Spur investigated anonymizing infrastructure after a leaked dataset tied IP address 156.59.13[.]153 to activity targeting organizations in South Korea and Taiwan, while the leak author attributed the activity to Kimsuky and Spur explicitly left that attri…
BTC Turk suffered a $51.7 million hot-wallet theft in August 2025 after private keys were reportedly compromised, repeating a similar $55 million breach from June 2024. The attackers moved assets across Ethereum, Avalanche, Arbitrum, Base, Optimism, Mantl…