Kimsuky-linked operators distributed a malicious LNK disguised as a seafood ingredient purchase-review request to South Korean users. Execution displayed a legitimate HWP decoy while extracting PowerShell and JavaScript components, establishing a schedule…
« Reports in 2026
553 reports
Kimsuky-linked operators distributed a malicious LNK disguised as a seafood ingredient purchase-review request to South Korean users. Execution displayed a legitimate HWP decoy while extracting PowerShell and JavaScript components, establishing a schedule…
Security Alliance handled 45 incidents between August 25 and 31, including a DPRK intrusion associated with $1.5 million in reported losses. The organization identified six domains observed that week as confirmed DPRK/UNC1069 infrastructure, several of wh…
SafeDep uncovered an npm dependency chain in which `ioredis-xyz` silently resolved `redis-type-xyz` and then the malicious `ulid-xyz` package, whose postinstall hook launched a cross-platform remote access trojan. The implant persisted as MicrosoftSystem6…
Arkham identified Lazarus-linked wallets selling more than $30 million in bitcoin through Hyperliquid over three weeks. The proceeds were converted into ether and solana and then transferred to Kraken, LBank, and KuCoin, although CoinDesk could not determ…
LNK shortcut files were the leading delivery format among APT attacks AhnLab detected against South Korean targets in July 2026. The documented infection chains used PowerShell, AutoIt, HTA files, scheduled tasks, DLL side-loading, GitHub, Google Drive, D…
Spear-phishing was the predominant delivery method observed against South Korean targets in July 2026, with malicious LNK files accounting for the largest share. The documented chains used PowerShell, AutoIt, HTA files, scheduled tasks, DLL side-loading, …
Huntress investigated five people employed across healthcare, financial services, IT, sales and marketing, and medicine who were assessed as likely DPRK remote workers using fraudulent or stolen identities. Correlated evidence included Astrill VPN and IPR…
PolinRider operators compromised a legitimate developer's GitHub identity and repeatedly used it to distribute DPRK-attributed NullReceiver malware through `fetch-page-assets` and other npm packages. Although npm removed version 1.2.9, the underlying `.vs…
Attackers targeted a Ukrainian civil society representative with a personalized collaboration email sent from a genuine Gmail account, withholding the malicious link until the recipient replied. A Codeberg-hosted archive contained an LNK file disguised as…
DPRK espionage groups Konni and Kimsuky have expanded into cryptocurrency-focused operations using distinct but increasingly sophisticated infection chains. Konni targeted crypto professionals with disguised AppleScript files, fake macOS password dialogs,…
A DPRK-linked fake recruiter sent a Bitso developer a malicious coding challenge containing cross-platform PowerShell and Bash stagers. The scripts created a hidden `.vscode` directory, inspected or updated Node.js, and installed a previously unseen obfus…
Attackers used a compromised crates.io maintainer account to publish malicious versions of arrayref, internment, and append-only-vec that pulled in a typosquatted dependency whose build script executed during compilation. The second stage harvested browse…
North Korean operatives use stolen or synthetic identities, AI assistance, domestic facilitators, VPNs, and laptop farms to obtain legitimate remote-work access inside companies and government agencies. A joint BCA LTD, NorthScan, and ANY.RUN investigatio…
A compromised crates.io account published `arrayref` 0.3.10 with a dependency on the typosquatted `proc-macro1` crate, causing malicious code to run automatically during Cargo builds. The dependency's build script reconstructed an obfuscated URL, download…