Microsoft describes how Jasper Sleet, a North Korea-aligned fraudulent IT worker operation, exploits remote hiring workflows to gain trusted organizational access. The actors use stolen or fabricated identities, AI-assisted personas, and role-specific app…
« Reports in 2026
593 reports
ANY.RUN attributes an active ClickFix-style macOS campaign to Lazarus Group, with fake meeting lures delivered through Telegram and impersonated Zoom, Teams, or Google Meet pages. Victims are instructed to run terminal commands that install the Go-based M…
SlowMist frames the Kelp DAO rsETH and LayerZero incident as a cascading DeFi failure involving liquid restaking tokens, cross-chain bridge verification, and lending-protocol collateral assumptions. The interview says LayerZero attributed the attack to La…
A forged LayerZero message authenticated by KelpDAO's sole configured DVN caused its Ethereum OFTAdapter to release 116,500 rsETH, worth about $292 million, on April 18, 2026. The token, adapter, and LayerZero on-chain contracts operated as designed; the …
Security Alliance reports that DPRK-linked actors stole 116,500 rsETH on April 18, 2026 by fraudulently triggering an attestation from the LayerZero DVN configured as the sole validator for the Kelp DAO OApp. Kelp blocked the attacker within about an hour…
Kelp says rsETH was drained on April 18 through a forged cross-chain message after two LayerZero-hosted RPC nodes were compromised and a third RPC node was hit by a simultaneous DDoS attack. The statement frames the incident as an attack on LayerZero infr…
CISA warns that compromised Axios npm releases [email protected] and [email protected] injected the malicious dependency [email protected] into developer environments. The dependency downloads multi-stage payloads from actor-controlled infrastructure, including…
NoxHunt uses infostealer telemetry and ZachXBT’s prior findings to examine compromised systems tied to suspected DPRK overseas IT worker operations. The activity centers on fraudulent remote development work supported by VPN obfuscation, fake identities a…
KelpDAO’s April 18, 2026 exploit involved about $290 million in losses and is described as likely attributable to DPRK’s Lazarus Group, specifically TraderTraitor. The incident was isolated to KelpDAO’s rsETH configuration because it used a 1-of-1 LayerZe…
Web3Firewall analyzes the reported 2026 KelpDAO exploit as a cross-chain DeFi infrastructure incident affecting rsETH bridge operations rather than a simple standalone smart-contract bug or phishing case. The article says the attack caused roughly $290–29…
FalconFeeds summarizes UNC1069 as a financially motivated North Korean actor linked to the Reconnaissance General Bureau and active in cryptocurrency and developer-supply-chain targeting. The February 2026 intrusion described in the excerpt began with a h…
AhnLab observed the Lazarus group exploiting an AnySign4PC vulnerability in a watering-hole attack against the financial-sector ecosystem, enabling remote code execution. Multiple watering-hole distribution sites remained in use, indicating continuing exp…
Axios maintainer access was compromised to publish malicious [email protected] and [email protected] releases that added the typosquatted dependency [email protected] without changing the main Axios source. The malicious dependency used a postinstall hook to ru…
Breakglass Intelligence maps a large Kimsuky credential-harvesting operation targeting South Korean users through Naver, National Tax Service, NHIS, NongHyup, National Pension Service, and Kakao impersonation themes. The investigation consolidates six inf…
The excerpt traces a confirmed DPRK IT worker using the GitHub identity icetrust0212 to primary development work on Verida Network’s proof-connector-dapp, which verifies zkPass proofs and issues Verida credentials for exchange KYC status. The author links…