Rekt analyzes the May 9, 2025 LNDFi theft as a $1.18 million drain enabled by Pool Admin control over modified Aave-style token contracts. The article notes ZachXBT's DPRK claim but focuses on the on-chain mechanics: a deployer granted Pool Admin rights, …
« Reports in 2025 »
792 reports
AhnLab's April 2025 APT trend report summarizes multiple regional threat activities, including North Korean groups exploiting South Korean software ecosystems. It describes Konni spear-phishing campaigns impersonating Korean government agencies and delive…
AhnLab's April 2025 APT trend report highlights two DPRK-relevant campaigns. Konni used spear phishing that impersonated the Korean National Police Agency and National Human Rights Commission, first encouraging replies and then delivering LNK and AutoIT-b…
LND attributed its May 9, 2025 breach to a developer it unknowingly hired who later proved to be an undercover DPRK IT worker. The attacker gained access to administrative keys and drained about $1.27 million through unauthorized transactions, prompting L…
Alyac reports a backdoor distributed with a valid certificate from a well-known Korean company, likely to reduce user suspicion and evade detection. The malware is an SCR executable disguised with a PDF-like icon and extracts a decoy PDF to the user's tem…
CYFIRMA profiles Group123 as a North Korean state-sponsored espionage group active since at least 2012 and tracked as APT37, Reaper, ScarCruft, and related aliases. The report describes targeting in South Korea, Japan, Vietnam, the Middle East, and other …
DTEX characterizes North Korea’s cyber program as a broad ecosystem combining espionage, system intrusions, cryptocurrency theft, fraud, and covert IT-worker activity rather than a set of neatly separated APT groups. The report says DPRK IT workers are em…
WIRED reports that DTEX and allied researchers exposed a large cluster of North Korean IT worker activity, including personas tracked as Naoki Murano and Jenson Collins. The workers allegedly operated from Laos before relocation to Russia, used false deve…
The report covers additional Contagious Interview activity in which North Korean threat actors expanded BeaverTail distribution beyond npm and GitHub to Bitbucket. Malicious npm packages were used to target software developers, sometimes through fake job-…
Strider describes North Korean IT workers using false or stolen identities to obtain freelance and remote developer roles at U.S. and other Western companies. The report links the activity to a state-directed revenue scheme that can expose employers to da…
Elliptic identifies Xinbi Guarantee as a Chinese-language Telegram marketplace that has processed at least $8.4 billion in USDT while selling money laundering services, stolen personal data, technology, and other services to fraud operators. The DPRK-rele…
In February 2025, TA406 began targeting government entities in Ukraine, delivering both credential harvesting and malware in its phishing campaigns. These credential harvesting campaigns took place prior to the attempted malware deployments and targeted s…
Konni is linked to a malicious Windows shortcut disguised as a KISA notification PDF that appears designed to exploit public concern around a recent SK Telecom breach. The shortcut abuses mshta.exe to run obfuscated JavaScript that launches PowerShell, wr…
The Medium analysis reviews two Base64-encoded PowerShell payloads attributed to Kimsuky-related activity and XWorm RAT. After decoding, the scripts show staged behavior: PowerShell and CMD execution, fileless or obfuscated script execution, download of a…
Flashpoint investigated the DPRK remote IT worker fraud scheme by pivoting from domains named in a December 2024 US indictment into compromised credential and infostealer-log data. Analysts linked fake company domains, reused registrant email accounts, Pa…