An investigation maps a cluster of 14 or more DPRK-linked IT worker accounts that allegedly infiltrated Tokamak Network and contributed heavily to bridge, NFT marketplace, subgraph, and landing-page repositories. The excerpt identifies primary actor "jusd…
« Reports in 2026
593 reports
A thread links the fake identity "Taro Aikuchi" to a DPRK IT worker cluster labeled "215" through repeated numeric markers across GitHub handles, email addresses, commit metadata, and aliases. The excerpt connects 0xbomb215, xsen215, highgoal215, and rela…
South Korean authorities warn that Midnight and Endpoint ransomware infections have been observed against domestic SMEs, especially manufacturers, with additional cases in retail, energy, and public-sector environments. The attackers first compromise IT s…
Trend Micro’s 2025 APT report frames North Korea as an “Asymmetric Saboteur” using AI to automate cybercrime and support state priorities such as missile funding. The DPRK-relevant section is strategic rather than IOC-driven, emphasizing AI-assisted recon…
KrCERT and the Korean National Police Agency warn that Midnight, also called Endpoint, ransomware incidents against South Korean small and medium-sized businesses are increasing through malicious email campaigns. The advisory says attackers use lures disg…
Microsoft attributes a macOS intrusion chain to Sapphire Sleet, a North Korean state actor focused on cryptocurrency, finance, venture capital, and blockchain targets. The campaign uses recruiter-style social engineering to make victims run a fake “Zoom S…
A malicious npm package named js-logger-pack evolved from harmless probes into a full multi-platform infostealer and later a HuggingFace-hosted binary dropper. Weaponized versions installed a Linux SSH backdoor, exfiltrated Telegram Desktop sessions, stol…
The Justice Department said Kejia Wang and Zhenxing Wang were sentenced for helping North Korean remote IT workers pose as U.S. residents and obtain jobs at more than 100 U.S. companies. The scheme used stolen identities of at least 80 U.S. persons, shell…
The thread explains why the author assessed the “Taro Aikuchi” applicant as a suspected DPRK fraudulent IT worker rather than a legitimate Japanese candidate. Evidence included fresh and inconsistent online identities, two-word-plus-number Gmail and Teleg…
Zerion says a team member’s device was compromised in an AI-enabled social engineering attack linked to a DPRK threat actor. The attacker gained access to logged-in sessions, credentials, and private keys for internal company hot wallets, leading to about…
Kimsuky is reported to have evolved its malicious LNK delivery by disguising shortcut files as HWP documents and adding XML, VBS, PowerShell, BAT, ZIP, and Python stages before final malware execution. Recent samples create a hidden C:\windirr directory, …
Cisco Talos reports that North Korean cyber operations in 2025 relied heavily on social engineering and insider access for both financial theft and espionage. The North Korea section highlights Contagious Interview activity by Famous Chollima, where fake …
Validin links UNC1069, overlapping with Bluenoroff, to fake meeting operations against cryptocurrency and Web3 professionals for financially motivated theft. Operators use fraudulent venture-capital personas, LinkedIn and Telegram outreach, Calendly-style…
Drift Protocol lost about $285 million after an attacker used pre-signed Solana durable-nonce transactions to take over a 2-of-5 Squads V4 multisig with no timelock. The attacker gained admin control, created fake CVT spot markets with manipulated oracles…
Bitso describes renewed Famous Chollima activity against crypto and financial organizations, including a suspicious job applicant encounter and a macOS malware kit the researchers call Mach-O Man. The infection chain starts with hijacked Telegram accounts…