AhnLab linked recent Xctdoor distribution tracked as Larva-26005 to CRAT attacks against South Korean users dating to 2020, which other security firms attributed to Lazarus. Shared AppX installation paths, runtime code-obfuscation methods, and the earlier…
« Reports in 2026
553 reports
A Greece-based security researcher, Vangelis Stykas, spent 22 months inside North Korean hackers' command-and-control servers and found evidence that 1,640 companies across 57 countries were impacted by DPRK hacking operations, with 700–800 suffering "rea…
Two state-trained IT specialists were arrested in Wonsan in July 2026 for running a smishing and voice-phishing scheme that drained e-wallet funds from North Korea's wealthy donju market entrepreneurs. The pair sent malware-laden text messages impersonati…
CrowdStrike attributes the poisoning of 131 AI framework packages to the North Korea-linked STARDUST CHOLLIMA adversary, demonstrating an effort to compromise trusted components upstream in the developer ecosystem. Such poisoned dependencies can provide a…
DPRK-linked Contagious Interview operators embedded NullReceiver in the trojanized npm packages bianira-ui and fluid-type-ui. The technique retrieves an attacker's latest zero-value, zero-data Ethereum transaction and decodes a C2 IP address from the reci…
A newly surfaced version of North Korea’s SiliVaccine antivirus replaces the stolen Trend Micro engine found in 2018 with ClamAV signatures and Malheur-based behavioral clustering. Internal artifacts still point to suspected developer PGI, while the user-…
AFX attributes its July 2026 custody-bridge theft to UNC4899 / TraderTraitor after a developer cloned a malicious DEX repository offered through a fake job approach. A modified Git post-checkout hook launched the initial payload, and the attacker later pe…
North Korean IT workers use forged or borrowed identities, third-party facilitators, and concealed remote-access arrangements to obtain employment and remit income to state-linked agencies supporting prohibited weapons programs. The workers can also creat…
North Korean IT workers use forged identities and third-country proxies to obtain remote jobs and remit salaries to DPRK agencies that support nuclear and ballistic missile programs. The joint alert says they may pose insider risks involving data exfiltra…
DPRK's PolinRider campaign automatically poisoned legitimate npm packages and Go modules after compromising developer machines, rather than deliberately selecting high-value packages for account takeover. OpenSourceMalware linked 20 analyzed packages thro…
North Korean actor MIDNIGHT NEPTUNE, formerly UNC1069, used a socially compromised maintainer account to introduce a malicious dependency into `axios`, deploying the WAVESHAPER.V2 backdoor and potentially exposing a package ecosystem with more than 100 mi…
PLAINBIT reconstructed a watering-hole intrusion in which a compromised trusted website exploited a vulnerable third-party security component and installed DLL backdoors without requiring a user to launch a file. One chain modified SageThumbs-related shel…
S2W analyzed three malware clusters targeting South Korea that combine legitimate-process abuse, DLL side-loading, encrypted payload staging, and manual PE mapping. Two chains deploy SIGNBT v0.0.1 or v1.2 from service-registry blobs or embedded containers…
South Korean security authorities warn that state-sponsored hacking groups are targeting Korean individuals and companies through phishing emails disguised as resumes, recruitment proposals, donations, or investment materials. The attackers also compromis…
State-sponsored attackers compromised legitimate South Korean websites and inserted exploit code targeting vulnerabilities in locally deployed security software, enabling drive-by malware installation. The recovered chains used ChaCha20 or AES-CBC-128 enc…