Genians links Operation GitPower to Kimsuky, which uses spearphishing, malicious LNK files, obfuscated PowerShell, scheduled tasks, and Git repositories to collect system data and deploy encrypted AsyncRAT payloads. Infrastructure logs show the operators …
« Reports in 2026
508 reports
Bybit filed a U.S. civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group over the February 2025 theft from the exchange. A preliminary injunction freezes identified stolen assets and prohibits their transfer or dissip…
AhnLab linked recent Xctdoor distribution tracked as Larva-26005 to CRAT attacks against South Korean users dating to 2020, which other security firms attributed to Lazarus. Shared AppX installation paths, runtime code-obfuscation methods, and the earlier…
AhnLab linked recent Xctdoor distribution tracked as Larva-26005 to CRAT attacks against South Korean users dating to 2020, which other security firms attributed to Lazarus. Shared AppX installation paths, runtime code-obfuscation methods, and the earlier…
A Greece-based security researcher, Vangelis Stykas, spent 22 months inside North Korean hackers' command-and-control servers and found evidence that 1,640 companies across 57 countries were impacted by DPRK hacking operations, with 700–800 suffering "rea…
Two state-trained IT specialists were arrested in Wonsan in July 2026 for running a smishing and voice-phishing scheme that drained e-wallet funds from North Korea's wealthy donju market entrepreneurs. The pair sent malware-laden text messages impersonati…
CrowdStrike attributes the poisoning of 131 AI framework packages to the North Korea-linked STARDUST CHOLLIMA adversary, demonstrating an effort to compromise trusted components upstream in the developer ecosystem. Such poisoned dependencies can provide a…
DPRK-linked Contagious Interview operators embedded NullReceiver in the trojanized npm packages bianira-ui and fluid-type-ui. The technique retrieves an attacker's latest zero-value, zero-data Ethereum transaction and decodes a C2 IP address from the reci…
A newly surfaced version of North Korea’s SiliVaccine antivirus replaces the stolen Trend Micro engine found in 2018 with ClamAV signatures and Malheur-based behavioral clustering. Internal artifacts still point to suspected developer PGI, while the user-…
AFX attributes its July 2026 custody-bridge theft to UNC4899 / TraderTraitor after a developer cloned a malicious DEX repository offered through a fake job approach. A modified Git post-checkout hook launched the initial payload, and the attacker later pe…
North Korean IT workers use forged or borrowed identities, third-party facilitators, and concealed remote-access arrangements to obtain employment and remit income to state-linked agencies supporting prohibited weapons programs. The workers can also creat…
North Korean IT workers use forged identities and third-country proxies to obtain remote jobs and remit salaries to DPRK agencies that support nuclear and ballistic missile programs. The joint alert says they may pose insider risks involving data exfiltra…
DPRK's PolinRider campaign automatically poisoned legitimate npm packages and Go modules after compromising developer machines, rather than deliberately selecting high-value packages for account takeover. OpenSourceMalware linked 20 analyzed packages thro…
North Korean actor MIDNIGHT NEPTUNE, formerly UNC1069, used a socially compromised maintainer account to introduce a malicious dependency into `axios`, deploying the WAVESHAPER.V2 backdoor and potentially exposing a package ecosystem with more than 100 mi…
PLAINBIT reconstructed a watering-hole intrusion in which a compromised trusted website exploited a vulnerable third-party security component and installed DLL backdoors without requiring a user to launch a file. One chain modified SageThumbs-related shel…