NorthScan identified `fullstackdev0110`, `reo0603`, and `buddy0323` as a coordinated GitHub persona cluster displaying indicators consistent with DPRK IT worker activity. The strongest evidence involved `reo0603`, which repurposed an Indian developer’s po…
« Reports in 2026
593 reports
Kudelski Security tracked a DPRK-linked Contagious Interview operation in which actors posed as recruiters on LinkedIn, WhatsApp, Discord, and CodeMentor to pressure developers into running trojanized interview projects. A fake GitHub repository impersona…
JFrog identified a Lazarus-linked npm supply-chain campaign that hid malicious code in Rollup-themed lookalike packages and SVG utility second stages. The packages fetched a JSONKeeper payload, decrypted a remote stage from 216.126.236.244, and launched N…
Kimsuky-linked malware masqueraded as a Korea Institute for Military Affairs monthly military and security publication, using a document-like LNK file to start a staged infection chain. Hauri observed Dropbox and GitHub being abused to host and deliver VB…
Kimsuky used a Korean-language CHM lure about North Korean food-crisis and right-to-food material to launch hidden PowerShell, decode a VBScript bootstrap, and retrieve staged payloads from DynV6-hosted infrastructure. The retrieved VBScript profiled the …
AhnLab observed May 2026 South Korea-focused APT activity dominated by spear phishing, especially malicious LNK attachments and some CHM files. The attack chains used PowerShell, CMD, XML, JS, VBScript, BAT files, AutoIt, HTA, Python, and legitimate Windo…
AhnLab observed May 2026 domestic APT activity in South Korea dominated by spear-phishing delivery, especially malicious LNK files and some CHM-based attacks. The infection chains used PowerShell, curl, HTA, VBS, BAT, XML, JS, AutoIt, Python, DLL side-loa…
BBC Korea obtained computer recordings and internal messenger logs that show how North Korean IT workers are managed as part of an organized fake-employment operation rather than as isolated freelancers. The material and expert review describe layered rol…
OpenSourceMalware highlights Lazarus Group software supply chain techniques including malicious-version “sandwiching,” reuse of Aptos/Tron/BSC blockchain infrastructure for mutable C2, and embedded campaign-tracking strings in payloads. The episode cites …
IIJ-SECT observed a May 2026 Kimsuky-linked KimJongRAT campaign that redirected targets from emailed shortened links to malicious GitHub Releases ZIP files containing LNK payloads. The infection chain used mshta, obfuscated VBScript, Google Drive-hosted e…
Moonlock Lab identified a macOS cross-platform RAT masquerading as MicrosoftSystem64, with a JavaScript payload bundled inside a Mach-O binary through `__NODE_SEA_BLOB`. The malware provides full surveillance and remote-control capabilities, including ada…
North Korean APT activity in Q2 2026 combined cryptocurrency theft, supply-chain compromise, cloud-focused intrusions, and strategic espionage. Lazarus targeted cryptocurrency exchanges, DeFi platforms, software vendors, defense contractors, and technolog…
Darktrace observed a recurring intrusion pattern in which ClickFix-style social engineering led macOS users into execution, followed by AppleScript or other native scripting and sustained outbound signaling. The use case is explicitly tied to activity Mic…
Sapphire Sleet compromised the `ehindero` npm maintainer account and injected the malicious `[email protected]` dependency into 144 Mastra AI npm packages during an 88-minute window on June 17, 2026. The postinstall hook executed an obfuscated JavaScrip…
The malicious npm packages `chalk-ultra` and `vitest-cli` execute a hidden downloader that steals developer credentials, source code, browser data, and cryptocurrency-wallet information. The payload can replace Chrome's MetaMask extension with a persisten…