A DPRK-affiliated IT worker cell used female callers alongside developers to obtain remote technology jobs under fabricated identities. The operation generated more than 1,200 female personas, used stolen U.S. identity data, isolated accounts through ixBr…
« Reports in 2026
593 reports
Graphalgo malware was distributed through two Terraform providers and two Go modules, using conditional activation to remain inert outside specially crafted runtime conditions. Its Go-based RAT collects host information and receives encrypted commands thr…
Security Alliance observed DPRK operators reactivating intrusions first established six to twelve months earlier and searching retained access for valuable opportunities. DPRK-related incidents caused losses of 1.7 BTC and 14.2 ETH, including a fake Micro…
SOCRadar attributes Operation Conflict Compass to Konni with moderate confidence, linking the campaign to Ukraine-focused espionage through malicious LNK files and trojanized Zoom installers. The infection chain deploys VelvetCake, a lightweight PowerShel…
PolinRider compromised development branches of the Packagist package `visanduma/nova-two-factor` by hiding an executable loader inside `tailwind.config.js`. The loader derives rotating C2 addresses from Ethereum transaction recipient fields, then download…
Atlassian attributes Contagious Interview with high confidence to North Korea's Famous Chollima group, citing job-lure tradecraft, BeaverTail, OtterCookie and InvisibleFerret use, infrastructure overlap, and Astrill VPN activity. Hundreds of malicious rep…
SlowMist linked malicious development branches of the Packagist package visanduma/nova-two-factor to PolinRider and found a loader concealed after 507 spaces in tailwind.config.js. Laravel Mix execution queries Ethereum transactions to derive rotating C2 …
Synaptic Security maps Hangro, a North Korean state VPN, email, and real-time chat product derived from SoftEther and distributed to DPRK trade representatives abroad. The research documents a broken 2024 elliptic-curve certificate hierarchy alongside a s…
CloudSEK linked the GHAPPIER loader operation to the DPRK-associated PolinRider campaign after finding a byte-identical loader beside a payload that used PolinRider's published Ethereum dead-drop wallet. The operator compromised developer credentials, mod…
SentinelOne linked an intrusion at an Indian IT services provider to the DPRK-sponsored TraderTraitor group, finding the same FLATROOF and ROOFDECK macOS backdoors previously observed in the LayerZero compromise. Weaponized GitHub coding assignments used …
Japanese, U.S., Australian, and German authorities identify WaterPlum, commonly known as Contagious Interview, as a North Korean cyber actor operating under the 313 General Bureau alongside some DPRK IT workers. The group compromised at least 30,000 devic…
North Korea-linked actors focused on developers, software supply chains, remote hiring, and defense targets during August 2026. Famous Chollima continued PolinRider supply-chain activity and used Ethereum for covert command and control, while Jasper Sleet…
North Korea-linked actors focused on developers, software supply chains, remote hiring, and defense targets during August 2026. Famous Chollima continued PolinRider supply-chain activity and used Ethereum for covert command and control, while Jasper Sleet…
Socket identified PolinRider malware in four development versions of the Packagist package `visanduma/nova-two-factor`, tracing the changes to a compromised GitHub developer account that also accessed private repositories. The North Korea-linked operators…
UNC5342 used public blockchains to deliver credential-stealing malware to cryptocurrency developers targeted through fraudulent job interviews. Chainalysis linked the DPRK operation to a redundant relay in which TRON and Aptos transactions direct infected…