CSIS describes how North Korea uses third countries including China, Russia and Southeast Asian states to support cyber operations, cryptocurrency theft, sanctions evasion and intelligence collection. The report says DPRK operators route activity through …
« Reports in 2025 »
792 reports
A Korean analysis examines a suspected Kimsuky-linked Excel malware sample disguised as a bonus calculation spreadsheet. The workbook uses macros to read a download URL from Sheet1 cell A10001, escape command characters, and invoke curl through cmd.exe to…
Christina Marie Chapman was sentenced to 102 months in prison for helping North Korean IT workers obtain remote jobs at more than 300 U.S. companies, generating over $17 million for Chapman and the DPRK. The scheme used stolen, borrowed, and false U.S. id…
OFAC sanctioned Korea Sobaeksu Trading Company and Kim Se Un, Jo Kyong Hun, and Myong Chol Min for supporting DPRK sanctions evasion and revenue generation, including fraudulent IT worker activity. The release says Sobaeksu operates as a front company for…
The source maps suspected North Korean IT-worker GitHub accounts and aliases around the codezs17 cluster. It links Cryptogru, formerly aidenwong812 and alternatively Donald-romeo-1100, to initial commits, then describes codez17 replacing references to cry…
The FBI warns that North Korean IT workers continue targeting U.S. businesses to obtain fraudulent employment, access company networks, and generate revenue for the DPRK in violation of U.S. and U.N. sanctions. The activity relies on identity obfuscation …
ASEC identified RokRAT distribution through malicious Hangul Word Processor documents rather than the malware's more typical LNK-based delivery chain. A North Korea grain-store-themed lure embedded ShellRunas.exe and credui.dll as OLE objects, which the H…
WhoisXML API examined a BlueNoroff attack in which victims received a Calendly-themed meeting invite over Telegram that redirected them from an expected Google Meet flow to an actor-controlled fake Zoom domain. The infection chain triggered a malicious Ap…
Validin describes upgrades to its host-response history and artifact collection, then uses the Bybit heist attributed by the FBI to North Korea's Lazarus Group as TraderTraitor to demonstrate retrospective infrastructure hunting. By searching over eight m…
A Wall Street Journal excerpt says the FBI believes thousands of North Koreans have infiltrated American technology companies by using assumed U.S. identities to win remote jobs. The fragment frames the activity as a workforce fraud problem for U.S. firms…
Rekt attributes the CoinDCX incident to attackers who allegedly prepared the theft over several days, funding activity with 1 ETH from Tornado Cash before routing through FixedFloat, Polygon, deBridge and Solana. The article describes a July 18 drain of a…
GenDigital observed a multi-stage DeceptiveDevelopment-style attack chain that used a mock hiring assessment and fake camera-update flow to trick users into copying and running a malicious command disguised as an NVIDIA-related update. The infection downl…
ASEC observed RokRAT being distributed through malicious Hangul HWP documents instead of the LNK-based delivery more commonly associated with this malware. One lure used North Korea grain distribution content and embedded ShellRunas.exe and credui.dll as …
OFSI assesses that UK cryptoasset firms are almost certainly under-reporting suspected financial sanctions breaches and face direct compliance exposure from cryptoasset-related sanctions risks. The assessment states it is highly likely that UK-based crypt…
Cyvers assesses the $44.2 million CoinDCX operational-wallet breach as showing hallmarks of North Korea's Lazarus Group targeting centralized cryptocurrency exchanges. The attacker staged funds from Tornado Cash through FixedFloat, Polygon, and Solana, se…