NK Internet observed 175.45.176.97 in the DPRK IP range returning a 302 redirect to recoshield.com between May 14 and May 17, 2026, with headers showing Apache on Rocky Linux and PHP. Further probing exposed a captive portal-style framework that checked G…
« Reports in 2026
508 reports
AhnLab observed April 2026 APT activity against South Korean targets, with most infections beginning through spear-phishing emails that used spoofed senders, malicious attachments, and malicious links. The activity relied heavily on LNK files, PowerShell,…
A fake Pulsynk recruiting email targeted a smart-contract security developer with instructions to clone a GitLab repository and open it in VS Code or Cursor. The repository abused a `.vscode/tasks.json` folder-open task to install a malicious VS Code exte…
Fox-IT analyzed a Lazarus subgroup toolset used against financial and cryptocurrency organizations, overlapping with activity linked to AppleJeus, Citrine Sleet, UNC4736, and Gleaming Pisces. The intrusion chain uses DPAPILoader to decrypt victim-bound pa…
Chainalysis tracks how OFAC has increasingly added cryptocurrency identifiers to sanctions designations, with several DPRK-linked cases showing how wallets, exchanges, bridges, DeFi services, and mixers support sanctions evasion. The DPRK-relevant section…
Red Asgard frames Lazarus-attributed fake coding interviews as an execution path into developer workstations rather than a traditional external exploit. The lure asks a developer to clone and run an interview repository on a machine that may already hold …
Red Asgard identifies five trojanized browser extensions tied to a Lazarus/Contagious Interview extension layer, masquerading as Bitwarden, Phantom, TronLink, Trust Wallet, and a Brave/MetaMask-themed wallet. The extensions resolve their command-and-contr…
SANS ISC analyzes an obfuscated Node.js stealer uploaded as `extracted-decoded.js`, with a heavily obfuscated execution wrapper but plain-text embedded payload modules. The malware targets Windows through WSL, macOS, and Linux, stealing Chromium-family br…
Trend Micro reports that Void Dokkaebi, also known as Famous Chollima, has migrated InvisibleFerret from readable Python scripts into Cython-compiled `.pyd` modules on Windows and `.so` modules on macOS. The campaign remains focused on software developers…
OpenSourceMalware discussed three malicious npm packages tied to the actor behind the March Axios compromise, saying they had quietly harvested developer credentials since early April. The DPRK-linked activity was framed as supporting parallel Contagious …
AhnLab's April 2026 financial-sector review links WGear RCE exploitation to DPRK-relevant activity, noting that Andariel has repeatedly abused the vulnerability. In observed cases, the WGear process launched mshta to retrieve external HTML, download and e…
The episode covers an eleven-hour forensic window into a live adversary server tied to a Lazarus-attributed fake interview campaign. Researchers preserved a contested Windows machine while two password changes were occurring, exposing the operator workben…
EndPoint, formerly known as Midnight, is a Babuk-derived ransomware family that targets Windows, ESXi, and NAS environments and uses double extortion through encryption and data-leak threats. The malware supports argument-controlled encryption scope, dele…
OX Security identified a malicious npm package, terminal-logger-utils, with keylogger, infostealer, and RAT behavior and linked the activity to previously documented North Korean supply-chain campaigns. The package is triggered through a postinstall hook …
WhoisXML API mapped DNS infrastructure from the UNC1069 compromise of the axios NPM package, which delivered the cross-platform WAVESHAPER.V2 backdoor through malicious `plain-crypto-js` post-install execution. The analysis consolidated five subdomains, s…