APT-C-26 (Lazarus) added a dedicated keylogging component, KKernel.exe, to a previously observed custom remote desktop surveillance platform. It installs as KKernelService, escapes Session 0 by spawning an agent in the active user session, and restarts th…
« Reports in 2026
593 reports
Checkmarx identified seven malicious npm packages that impersonated Vite-related scopes and delivered an obfuscated remote-access trojan through Tron, Aptos, and Binance Smart Chain infrastructure. Shared wallets, XOR keys, loader structure, and payloads …
S2W attributes BirdCall to the North Korea-backed ScarCruft group and analyzes an Android spyware sample created by repackaging the legitimate Zangi messenger application. BirdCall uses separate Zoho WorkDrive accounts for command delivery and exfiltratio…
APT37 likely used spearphishing emails impersonating a real academic conference to deliver an ISO containing a PDF-disguised PIF loader. The EMBED_PAYLOAD_v2 loader displayed a legitimate decoy document while decoding shellcode and injecting an x64 RokRAT…
APT37 likely used spearphishing emails impersonating a real academic conference to deliver an ISO containing a PDF-disguised PIF loader. The EMBED_PAYLOAD_v2 loader displayed a legitimate decoy document while decoding shellcode and injecting an x64 RokRAT…
CYFIRMA assesses that Famous Chollima, also known as Lazarus Group, is expanding the PolinRider software supply-chain campaign beyond npm into Go Modules, Packagist, and Chrome extensions. The suspected activity compromises legitimate GitHub repositories …
`nodemon-sudo` v3.1.16 is a malicious npm lookalike that copies legitimate nodemon while adding an unused dependency on `tslint-conf`, a repackaged pino logger containing the backdoor. The payload avoids install hooks and import-time execution; it runs on…
PolinRider, a DPRK-linked Lazarus Group / Contagious Interview supply-chain campaign, expanded from compromised GitHub repositories into Go modules and Packagist packages because those ecosystems publish directly from git repositories and tags. OpenSource…
SlowMist’s mid-year 2026 blockchain security and AML report names Lazarus Group as a North Korean state-sponsored actor that remained active in cryptocurrency attacks. The DPRK-focused section says Lazarus used supply chain compromise, social engineering,…
Financial Security Institute's DeepChain report analyzes cross-chain digital-asset security through Lazarus-linked bridge incidents and laundering patterns. It says North Korean Lazarus-linked or suspected activity accounts for about 63% of reviewed cross…
North Korean operators are linked to Gaslight, a Rust-based macOS stealer and backdoor analyzed by SentinelOne and covered by Moonlock. The malware collects browser data, Terminal command histories, installed-application and process lists, system profile …
Ossprey identified 298 active payload URLs associated with the DPRK's Contagious Interview campaign after malicious npm packages led investigators into a JSONkeeper dead-drop namespace. The operation deployed BeaverTail to steal Chromium credentials, cryp…
Attackers conducted a record 207 crypto hacks in H1 2026, but total losses fell to USD 972 million from USD 2.3 billion in H1 2025. TRM attributes about USD 643 million, or 66% of all stolen funds, to North Korea-linked activity, driven mainly by April at…
Socket reports that PolinRider, a supply-chain campaign linked to North Korean threat actors in the Contagious Interview / Famous Chollima cluster, has expanded beyond npm into Packagist, Go modules, and a Chrome extension. The research identifies 162 mal…
S2W TALON analyzes laundering infrastructure used in North Korea-linked cryptocurrency theft operations, citing Ronin Bridge, Horizon Bridge, Atomic Wallet, DMM Bitcoin, and Bybit as cases tied by public reporting to Lazarus, TraderTraitor, and related ac…