CyberBlade Security examines how North Korea’s cyber apparatus is connected to education, military infrastructure, and regime-controlled facilities in Pyongyang’s Mangyongdae district. The analysis focuses on Kim Il Sung Military University, described as …
« Reports in 2025 »
792 reports
ANY.RUN analyzes PyLangGhost RAT as a Python-based evolution of GoLangGhostRAT linked in the excerpt to the Lazarus subgroup Famous Chollima. The malware is delivered through targeted ClickFix social engineering against technology, finance, and cryptocurr…
Bybit lost more than $1.4 billion in ETH after Lazarus-linked operators compromised Safe{Wallet} infrastructure and manipulated the multisignature transaction flow used for a routine cold-to-warm wallet transfer. The excerpt describes initial access throu…
A U.S. civil forfeiture complaint seeks approximately 1,008,902.606307 USDT tied to alleged identity theft, computer fraud, wire fraud, money laundering, and related conspiracies. The excerpt defines the legal basis for seizing virtual-currency property d…
CNN reports that thousands of North Korean IT workers use stolen or fabricated U.S. identities to pose as Western developers, engineers, and technology consultants. The operation relies on AI-generated resumes and headshots, face-masking tools, VPNs, remo…
BigONE reported that a July 16, 2025 attack drained about $27 million from its hot wallets without exposing private keys. HackenProof attributed the intrusion path to social engineering against a key developer, followed by compromise of the developer’s de…
The Chinese source uses a Lazarus-inspired ByBit/Safe{Wallet} scenario to explain how front-end tampering can redirect cryptocurrency transactions without crashing the service or visibly altering the user experience. The described attacker studies Next.js…
CrowdStrike reports that DPRK-nexus FAMOUS CHOLLIMA infiltrated more than 320 companies over the past 12 months, a 220% year-over-year increase. The activity centers on North Korean IT workers using generative AI throughout hiring and employment, includin…
The analysis attributes a malicious LNK file disguised as an HWP document to Kimsuky and shows it abusing PowerShell to locate a specific-size shortcut file and extract embedded data. The script reads bytes from offset 0x17DC, XOR-decrypts them with 0x8C,…
A SwimSec WeChat post maps DPRK Lazarus activity against Web3 and cryptocurrency exchanges at a high level. The preserved text says it summarizes related attack groups and invites discussion of Lazarus TTPs, IOAs, and IOCs, especially TraderTraitor/UNC489…
Genians identifies a new RoKRAT variant used by APT37 and delivered in South Korea through a compressed archive containing an unusually large malicious LNK file. The shortcut masquerades as a national intelligence and counterintelligence manuscript and em…
Genians analyzes an APT37 RoKRAT campaign in Korea that used oversized LNK files, malicious HWP/OLE content, DLL side-loading, and JPEG steganography to load payloads. One infection chain hides a decoy HWP document, batch script, PowerShell command, and s…
The excerpt presents an adversary simulation modeled on Famous Chollima activity against job seekers and software developers, relying on public reporting about North Korean campaigns targeting job hunters. The attack chain begins with fake online intervie…
KISA warns that SGA Solutions' discontinued TrustPKI Enterprise product contains a vulnerability caused by insufficient verification. The advisory instructs organizations and users to remove the product immediately if it is installed on PCs because the pr…
Google's H2 2025 Cloud Threat Horizons material flags North Korea among state-sponsored actors advancing social engineering tactics in the cloud threat landscape. The excerpt also highlights abuse of trusted cloud storage services for malware delivery and…