Google Threat Intelligence Group’s unified actor-naming system will assign North Korea-attributed threat clusters the category word NEPTUNE as the second element of a two-word cryptonym. The first word will uniquely identify the tracked actor, while the s…
« Reports in 2026
447 reports
JUMPSEC recovered source code and malware from a BlueNoroff platform that impersonates Zoom and Microsoft Teams meetings, profiles cryptocurrency wallets, and delivers ClickFix payloads to Windows and macOS victims. Operators approached targets through hi…
Discharged veterans of a North Korean military intelligence cyber unit allegedly recruited elite university-trained IT personnel to breach the Chosun Central Bank and Foreign Trade Bank. The group reportedly diverted state trade funds in small increments,…
AhnLab observed June 2026 domestic APT activity delivered primarily through spear-phishing emails and malicious LNK files, and the source categorizes the analysis under Kimsuky. The documented chains used PowerShell, AutoIt, HTA files, GitHub-hosted paylo…
AhnLab's June 2026 monitoring found that APT attacks in South Korea predominantly began with work-themed spear phishing and malicious LNK files, and the source categorizes the activity under Kimsuky. The observed chains used PowerShell, AutoIt, curl, HTA …
Kimsuky is targeting foreign-affairs personnel with spearphishing lures that execute malicious LNK files and install PebbleDash, PrxClient, RDP tooling, UAC bypass utilities, and a keylogger. PebbleDash provides extensive remote command, file-transfer, pr…
Sapphire Sleet used a compromised Telegram contact and a fake Microsoft Teams meeting to persuade an ORO team member to run a malicious AppleScript on macOS. The intrusion captured the system password, deployed a browser extension for keylogging, clipboar…
DTEX analyzed records from an exposed internal DPRK payment server containing 390 accounts, chat logs, cryptocurrency transactions, and organizational self-identifications. Workers reported crypto or fiat transfers through luckyguys.site to administrator …
A malicious LNK disguised as a game-character design file launches a multistage PowerShell infection chain that checks the analysis environment and collects system information. The malware generates aes.js at runtime to steal cookies for command-and-contr…
Kimsuky compromised South Korean groupware developers through a mail-server vulnerability and suspected spearphishing, then used stolen internal information and credentials to reach downstream customer systems. The attackers deployed Gomir and HttpTroy al…
Kimsuky compromised South Korean groupware vendors from 2025 through early 2026 through mail-server vulnerability exploitation and likely spear-phishing, then used stolen vendor information to breach downstream customers. ENKI identified BirdTroy and Driv…
Famous Chollima, a North Korean-aligned actor also known as Wagemole, uses fake cryptocurrency and Web3 job interviews to pressure targets into executing clipboard-substituted ClickFix commands. Windows victims receive a Nuitka-compiled PylangGhost RAT, w…
North Korea places trained software developers in Western remote jobs under stolen or fabricated identities, using their salaries to generate state revenue while gaining access to corporate systems and data. AI-generated application materials, manipulated…
Elastic identified REF9403, a DPRK-aligned Contagious Interview campaign that delivered trojanized coding challenges through fake developer recruitment and concealed payload fragments in SVG flag images. Running the project reconstructed and executed an O…
Kimsuky continued spear-phishing operations in 2026 by impersonating diplomatic personnel and using malicious LNK attachments with diplomatic-themed decoy documents. The infection chains deployed PebbleDash for remote control, PrxClient to relay C2 traffi…