AhnLab contrasts two endpoint-compromise paths observed in South Korea: targeted phishing that launches BAT, executable, VBScript, and PowerShell stages, and watering-hole attacks that exploit locally installed Non-ActiveX security software. The demonstra…
« Reports in 2026
593 reports
Enki WhiteHat links a series of compromises at South Korean groupware vendors and their customers to Kimsuky, with attackers exploiting server vulnerabilities and spear-phishing employees to establish initial access. The intrusions deployed Gomir, HttpTro…
Sapphire Sleet used a compromised Telegram contact and a fake Microsoft Teams meeting to persuade an ORO team member to run a malicious AppleScript on macOS. The intrusion captured the system password, deployed a browser extension for keylogging, clipboar…
DTEX analyzed records from an exposed internal DPRK payment server containing 390 accounts, chat logs, cryptocurrency transactions, and organizational self-identifications. Workers reported crypto or fiat transfers through luckyguys.site to administrator …
A malicious LNK disguised as a game-character design file launches a multistage PowerShell infection chain that checks the analysis environment and collects system information. The malware generates aes.js at runtime to steal cookies for command-and-contr…
Kimsuky compromised South Korean groupware developers through a mail-server vulnerability and suspected spearphishing, then used stolen internal information and credentials to reach downstream customer systems. The attackers deployed Gomir and HttpTroy al…
Kimsuky compromised South Korean groupware vendors from 2025 through early 2026 through mail-server vulnerability exploitation and likely spear-phishing, then used stolen vendor information to breach downstream customers. ENKI identified BirdTroy and Driv…
Famous Chollima, a North Korean-aligned actor also known as Wagemole, uses fake cryptocurrency and Web3 job interviews to pressure targets into executing clipboard-substituted ClickFix commands. Windows victims receive a Nuitka-compiled PylangGhost RAT, w…
North Korea places trained software developers in Western remote jobs under stolen or fabricated identities, using their salaries to generate state revenue while gaining access to corporate systems and data. AI-generated application materials, manipulated…
Elastic identified REF9403, a DPRK-aligned Contagious Interview campaign that delivered trojanized coding challenges through fake developer recruitment and concealed payload fragments in SVG flag images. Running the project reconstructed and executed an O…
Kimsuky continued spear-phishing operations in 2026 by impersonating diplomatic personnel and using malicious LNK attachments with diplomatic-themed decoy documents. The infection chains deployed PebbleDash for remote control, PrxClient to relay C2 traffi…
Stealer-log analysis exposed changes in the public and private network infrastructure supporting North Korean fake IT workers, including an apparent route through Russian exit nodes and VPN endpoints in the United States and Japan. Internal records linked…
Consensys hired a consultant using the alias “Tyler Knapp” who was subsequently identified through the company's investigation as connected to North Korea. The consultant contributed to core and mobile MetaMask code, including functionality related to cry…
OpenSourceMalware attributes the ChainVeil and ViteVenom npm supply-chain operations to PolinRider, a North Korean Lazarus Group campaign, based on identical TRON wallets, an Aptos address, XOR keys, campaign markers, and targeting patterns. The blockchai…
OpenSourceMalware identified 2,417 newly compromised repositories in July, bringing PolinRider's confirmed footprint to 4,367 repositories across 2,152 owners—roughly 6.5 times the March count. The source attributes PolinRider to the North Korean Lazarus …