CYFIRMA profiles Lazarus Group as a North Korean state-sponsored threat actor active since at least 2009, combining espionage, political objectives, and financially motivated cybercrime. The excerpt lists a broad alias set including Hidden Cobra, APT38, A…
« Reports in 2025 »
792 reports
SlowMist analyzed a Web3 interview lure in which a self-proclaimed Ukrainian team asked a target to clone the EvaCodes-Community/UltraX GitHub repository. The project replaced a previously removed malicious dependency, [email protected], with [email protected]…
A Korean malware analysis attributes a malicious HWP document named “250615_Grain Sales Office Operations Status.hwp” to APT37/Reaper and describes it as RokRAT-themed activity. The lure content concerns grain sales and distribution in Pyongyang, indicati…
Seongsu Park’s DEF CON material examines how North Korean cyber operations have evolved from broad umbrella labels into multiple specialized clusters with overlapping tools, infrastructure, and mission sets. The slides describe Lazarus-linked history, Kim…
Leaked material attributed in the excerpt to Kimsuky shows recent phishing against South Korea's Defense Counterintelligence Command, with auth logs containing dcc.mil.kr users and other Korean services including spo.go.kr, korea.kr, Daum, Kakao, and Nave…
A Bybit hack case study attributes a $1.46 billion cryptocurrency theft to North Korea’s Lazarus Group and uses it to explain modern crypto laundering workflows. The excerpt describes two intrusion paths: malicious JavaScript injected into a third-party w…
North Korean fake-interview operations are described as delivery paths for BeaverTail, InvisibleFerret, OtterCookie, and ChaoticCapybara. The presentation analyzes those malware families, reverse-engineers their techniques, and modifies samples to expose …
The DEF CON material uses the February 2025 Bybit theft as a case study for tracing large-scale cryptocurrency laundering after a manipulated transaction changed the Safe wallet execution path and enabled attacker-controlled transfers. It describes rapid …
Moonlock links North Korean fake IT worker operations to the growth of macOS stealer malware used to obtain identities, credentials, and crypto-related data. The report says stolen personal information helps DPRK operatives pose as legitimate job applican…
A Stardust Chollima adversary simulation recreates the 2018 compromise of Chilean interbank network Redbanc, where PowerRatankba was delivered through a fake job-application lure. The attack chain centers on social engineering over LinkedIn/Skype, a GUI d…
A Konni-attributed LNK malware sample impersonates a Korean National Tax Service overseas financial account declaration form and abuses Windows PowerShell to unpack and run embedded payloads. The obfuscated script searches for a matching .lnk file by size…
PIOLINK analyzed HappyDoor malware activity attributed in the report to the Kimsuky group, described as a North Korea-linked APT focused on espionage against South Korean and other Asian diplomatic, defense, government, and military research targets. The …
Leaked data reviewed by WIRED and researcher SttyK exposes the internal workflow of an alleged North Korean IT-worker operation that tracks job applications, fake identities, hardware, earnings, and team budgets across Google, GitHub, Slack, and spreadshe…
A spear-phishing operation targeted a specific person at a South Korean nonprofit policy research institute by impersonating a domestic media employee during an otherwise plausible column-submission workflow. The attack delivered a password-protected ZIP …
S2W TALON attributes a postal-code update lure campaign against South Korean users to ChinopuNK, an internally tracked ScarCruft subgroup associated with Chinotto malware. The infection chain begins with a malicious LNK in a RAR archive, drops an AutoIt l…