South Korea’s threat landscape is described as heavily shaped by North Korea-linked actors targeting government, defense, finance, cryptocurrency, media, policy, and technology sectors. Lazarus Group is associated with both espionage and financially motiv…
« Reports in 2026
508 reports
The article frames unauthorized access to a controlled AI model preview through a third-party contractor as a supply-chain and sanctions problem relevant to DPRK cyber operations. It argues that North Korea-linked actors such as Lazarus and TraderTraitor …
The Risky Biz Between Two Nerds episode discusses what the North Korean hack of Drift may reveal about future hacking trends. The excerpt identifies the content as an analytical podcast conversation between Tom Uren and The Grugq rather than a technical I…
Arctic Wolf attributes a targeted intrusion against a North American Web3 and cryptocurrency company with high confidence to BlueNoroff, a financially motivated Lazarus Group subgroup. The attack began with spear-phishing that impersonated a Fintech legal…
LeenLee Country Club in Gapyeong disclosed a customer-data breach after police notified the company that its website server showed signs of malware infection. Korean police were tracking activity by a hacking group under North Korea's Reconnaissance Gener…
NK Internet tracks a DPRK-style fake developer and company cluster that pivoted after earlier Mentonex-related accounts and companies were taken down. The investigation connects Nixsora.com and GitHub personas such as vexxloso, trader389, walletdiscover10…
A KelpDAO cross-chain bridge failure released 116,500 rsETH after LayerZero's single required DVN accepted a forged Unichain-to-Ethereum message. The excerpt says preliminary attribution points to North Korea's Lazarus Group, while also noting unresolved …
Panther Threat Research tracked a DPRK-linked npm supply-chain campaign that published 108 malicious packages and 261 versions between March 20 and April 20, 2026. The activity is attributed with high confidence to Famous Chollima / DeceptiveDevelopment b…
Lazarus Group’s TraderTraitor cluster is preliminarily linked to a $292M KelpDAO rsETH bridge exploit that abused a 1-of-1 LayerZero DVN setup rather than a smart contract flaw. The attacker allegedly poisoned RPC infrastructure used by LayerZero’s DVN, f…
Malicious `js-logger-pack` versions used an npm `postinstall` script to download cross-platform `MicrosoftSystem64` Node SEA implants from Hugging Face, giving the operator persistent access on Windows, macOS, and Linux. The implant connects to `195.201.1…
The excerpt traces laundering after a reported North Korean theft of $292 million from Kelp DAO, describing pre-funded Tornado Cash wallets, cross-chain gas preparation, and a forged LayerZero message that released 116,500 rsETH. The actor rapidly convert…
A developer describes a highly polished fake recruiting process that used a realistic company website, apparent HR and engineering interviews, and a coding challenge to persuade the victim to run a supplied repository. The visible repo appeared clean, but…
The archived driver analysis alleges that North Korea’s Lazarus Group has weaponized the same class of Microsoft-signed OEM kernel driver weakness discussed in the post. The cited Dell WDTKernel.sys driver exposes 47 privileged commands without access con…
Attackers linked by LayerZero to DPRK Lazarus Group's TraderTraitor stole about $292 million in rsETH from KelpDAO's LayerZero bridge on April 18, 2026. The operation targeted off-chain verification infrastructure, compromising LayerZero-hosted RPC nodes …
Expel tracks HexagonalRodent as a high-confidence DPRK state-sponsored cluster focused on stealing cryptocurrency and NFTs from Web3 developers. The group uses fake job offers and coding assessments that are backdoored through VSCode tasks.json run-on-fol…