BBC reporting based on a rare interview with a defector describes North Korean IT workers using fake or borrowed identities to obtain remote jobs at Western companies. Jin-su said teams abroad in China, Russia, Africa, and elsewhere targeted US and Europe…
« Reports in 2025 »
792 reports
A Seoul ADEX 2025-themed LNK is assessed as suspected APT37 activity and likely RoKRAT. The shortcut poses as a PDF for an international UAV and defense exhibition, runs PowerShell through Pester.bat, shows a decoy document, and retrieves staged component…
Veracode identified twelve malicious npm packages tied to a persistent North Korean crypto-stealing campaign that targets developers through interview-style exercises. The packages used typosquatting and cloned legitimate-looking content, then executed ob…
DomainTools details a DPRK remote IT worker ecosystem coordinated around Reconnaissance General Bureau activity, including Andariel-linked Song Kum Hyok and facilitators who helped North Korean workers pose as legitimate remote hires. The scheme uses stol…
Sonatype reports that the North Korea-backed Lazarus Group is abusing open source package ecosystems as part of a strategic software supply-chain campaign. In the first half of 2025, Sonatype’s automated detection identified 234 unique malware packages in…
Plainbit and South Korea's NCSC analyze spear-phishing infrastructure used by suspected North Korea-backed groups in the first half of 2025. The report separates delivery infrastructure from credential-collection and storage infrastructure, noting that at…
The Lazarus Group’s Contagious Interview campaign is described as evolving its payload delivery for BeaverTail, InvisibleFerret, and OtterCookie across multiple malicious projects. The analyzed code uses external requests, URL-splitting, Vercel-hosted lur…
The Korean analysis attributes an electronic tax invoice-themed malware campaign to Kimsuky, using a disguised Windows shortcut named like a PDF invoice to execute hidden PowerShell. The LNK contains Base64-encoded script logic that writes and runs main.p…
Gunra expanded its ransomware operations with a configurable Linux variant capable of running up to 100 encryption threads. The malware uses ChaCha20 for file data and RSA to protect generated key material, supports partial encryption, and can target sele…
Aryaka Threat Research Labs attributes the activity to Kimsuky, also tracked as APT43, Thallium, and Velvet Chollima, and frames it as North Korean cyber-espionage supporting geopolitical, military, and economic intelligence collection. The campaign targe…
Flashpoint details DPRK remote IT worker operations in which North Korean operatives pose as freelance developers, IT staff, and contractors to gain trusted access inside organizations worldwide. The activity relies on long-lived fake personas, “parallel …
WOO X suffered a $14 million breach after a targeted phishing attack compromised a team member’s device and exposed access to the development environment. The attacker used that access to reach hot-wallet-related systems and coordinate withdrawals across …
TraderTraitor is presented as a North Korean financially motivated activity cluster focused on stealing cryptocurrency and other digital assets from blockchain and cloud-connected organizations. The excerpt ties the cluster to Lazarus Group, APT38, BlueNo…
InvisibleFerret is described as a Python-based backdoor used by Lazarus Group or Famous Chollima in Contagious Interview operations against developers, cryptocurrency workers, finance targets, and other technology professionals. The infection chain relies…
Genians analyzed Windows and Linux variants of Gunra ransomware, a family first observed in April 2025 with code-structure similarities to leaked Conti source code. The Windows build enumerates drives and user directories, excludes selected system and sec…