« Reports in 2026

508 reports

2026-05-19 • Bitso

Bitso described another suspected North Korean Chollima job applicant who attempted to interview for an engineering role under the claimed identity of Camilo Andrés Pantoja from Colombia. During the call, a Canary Token link exposed that the applicant con…

#ITWorker
2026-05-18 • Bridewell

Attackers are sharpening established methods rather than abandoning them, using offensive tooling, infostealers, ransomware affiliates, social engineering, and trusted-platform abuse with greater speed and resilience. Bridewell highlights adversary infras…

#Trend #NPM #T1541
2026-05-15 • North Scan

NorthScan links Beejern, an active Oklahoma LLC, to a suspected DPRK IT worker network through GitHub identity cycling, DPRK-associated developer personas, exposed Beejern credentials, and reused company infrastructure. The GoldenDev321 account previously…

#ITWorker
2026-05-14 • Kaspersky

Kimsuky has expanded its PebbleDash and AppleSeed-related operations with newly documented tooling, including the Rust-based HelloDoor backdoor, httpMalice, MemLoad/httpTroy, AppleSeed, HappyDoor, VSCode Remote Tunneling, and DWAgent. The campaigns use sp…

#Kimsuky #Phishing #AppleSeed #PebbleDash #BlackBanshee #VelvetChollima #GitHub #ADS #APT43 #RubySleet #Springtail #HappyDoor #JSE #SparklingPisces #HttpTroy #VSCode #T1059.003 #T1005 #T1041 #T1113 #T1071.001 #T1056.001 #T1027 #T1566.001 #T1547.001 #T1053.005 #T1059.001 #T1105 #T1219 #T1543.003
2026-05-14 • Krypt3ia

Krypt3ia assesses that enterprise AI systems are becoming high-value operational infrastructure because they ingest sensitive data, connect to internal workflows, and increasingly act with delegated authority. The North Korea-focused section argues that D…

#Trend