« Reports in 2026

504 reports

2026-08-10 • USCISA

Gunra evolved from a Conti-derived ransomware variant first observed in April 2025 into a structured ransomware-as-a-service operation with Windows and Linux encryptors. Its affiliates exploit vulnerable or weakly secured VPN and firewall appliances, stea…

#Ransomware #Gunra #T1555 #T1560 #T1083 #T1567 #T1539 #T1003 #T1105 #T1490 #T1486 #T1622 #T1133 #T1190 #T1530 #T1114 #T1098 #T1657 #T1550.002 #T1021.001 #T1106 #T1047 #T1021.002 #T1678 #T1070.003 #T1040 #T1572 #T1003.003 #T1078.002
2026-08-09 • JDT

North Korea combines nationwide network isolation, state-controlled application distribution, persistent device surveillance, cryptographic file restrictions, and physical enforcement to prevent citizens from accessing or sharing outside information. Andr…

#Slides #OpSec
2026-08-09 • Bitso

BCA LTD, NorthScan, and ANY.RUN recruited DPRK-linked Famous Chollima IT workers into a controlled DeFi company and recorded their activity through monitored Windows sandboxes. The investigation exposed false-identity and facilitator arrangements, remote-…

#Slides #ITWorker #FamousChollima