WOO X attributed a July 24, 2025 cryptocurrency-theft incident to suspected North Korea-linked activity, citing evidence for UNC4899 and later considering UNC4899 or UNC5565 involvement. The intrusion began when a developer accepted an open-source collabo…
« Reports in 2025 »
792 reports
Axios reports that North Korean remote IT worker operations have reached major U.S. companies, including Fortune 500 environments, as a sanctions-evasion revenue stream for Pyongyang. The scheme uses stolen or fabricated identities, AI-generated resumes a…
Leaked email datasets are used to profile DPRK IT worker tradecraft, with the source linking the activity to Microsoft’s Jasper Sleet classification and remote-work fraud against DApp, Web3, blockchain, and cryptocurrency companies. The analysis says 1,38…
AhnLab observed July 2025 APT activity in South Korea dominated by spear-phishing, with LNK-based delivery making up the largest share of identified cases. The LNK files executed malicious PowerShell commands, unpacked CAB archives, ran scripts such as BA…
Trellix attributes an active early-2025 espionage campaign against embassies and foreign ministries in Seoul to DPRK-linked actors, with infrastructure overlaps to known Kimsuky operations. The attackers sent at least 19 spear-phishing emails impersonatin…
A Korean malware analysis attributes the auto.py sample to Lazarus/Famous Chollima and identifies it as part of the PyLangGhost RAT tooling. The script is described as collecting Chrome extension local storage from multiple browser profiles, which could e…
North Korean hackers were accused in an OFSI-referenced assessment of stealing about £17m in Bitcoin, Ethereum, and other cryptocurrency from Lykke, a trading platform incorporated in Britain. The article says Lazarus was identified as a potential culprit…
A Korean OSINT discussion analyzes a leaked "APT Down North Korea Hacker" dump that allegedly exposed a suspected Kimsuky operator's virtual workstation and VPS images. The speakers describe phishing infrastructure, tools, recovered documents or source ma…
Leaked workstation and server material is presented as evidence of suspected Kimsuky activity against South Korean government, military, prosecution, foreign ministry, portal, media, and Taiwan-related targets. The excerpt describes spear-phishing infrast…
A leaked Kimsuky data set is described as exposing internal files and tools tied to backdoors, phishing frameworks, and reconnaissance activity after a compromise around early June 2025. The excerpted work.zip analysis highlights operator tooling rather t…
NSHC’s July 2025 threat actor roundup says SectorA was active against the software supply chain and developer ecosystem. The SectorA section describes typosquatted npm packages that deliver a malicious loader, collect system details, credentials, and cryp…
Sandfly analyzes a leaked Linux loadable kernel module rootkit from a suspected North Korean hacking-group data dump, noting that the broader Phrack material includes activity against South Korea and Taiwan with some overlap to Kimsuky tactics. The 2025 r…
DRATzarus, also tracked as ThreatNeedle, is described as a Lazarus Group remote access trojan used since at least mid-2020 against defense and aerospace organizations. The excerpt says delivery commonly relies on targeted spear-phishing with COVID-19 or f…
AhnLab observed July 2025 domestic APT activity in South Korea dominated by spear-phishing, with LNK-file delivery making up the largest share and watering-hole activity also noted. The LNK chains used embedded PowerShell to extract CAB files and decoy do…
A compromised DPRK IT worker device exposed a five-person operation managing more than 30 fraudulent identities to obtain developer jobs through purchased Upwork and LinkedIn accounts, government IDs, phone numbers, AI subscriptions, rented computers, VPN…