OpenSourceMalware found 11 malicious npm packages delivering WeaselBiscuit, a compact Node.js infostealer that executes an Npoint-hosted payload in memory and communicates with an HTTP C2 at 103.170.217.184:8787. It profiles infected systems, steals Chrom…
« Reports in 2026
593 reports
The Multilateral Sanctions Monitoring Team estimates that North Korea deployed 35,600 to 101,280 overseas labourers across at least 17 countries and generated roughly $450 million to $800 million for the DPRK government in 2025. The report documents wage …
S2W links two ransomware cases to Andariel within its H1 2026 landscape. Symantec evidence associated a U.S. healthcare intrusion using Medusa ransomware with the North Korea-backed group, although S2W tracks the activity separately as puNK-012 because th…
SEAL attributed approximately $2.9 million in losses to three DPRK intrusion cases involving Contagious Interview, a DPRK IT worker, and SINT-01 (Konni). Each successful intrusion occurred months before the resulting theft, with the actors maintaining acc…
Silent Push uncovered a Discord advertisement recruiting foreign facilitators to impersonate remote job applicants for a suspected North Korean IT worker. The operator offered facilitators 35% of earnings to provide their identities, appear in interviews,…
North Korean IT teams are expanding their remote-employment scheme by recruiting developers in countries such as Iran, Syria and South Africa to impersonate candidates, complete technical tests and establish contact with Western employers. Flare identifie…
Qihoo 360 attributes a multi-stage infection chain to Kimsuky (APT-C-55), beginning with a trojanized OrionQuests installer that drops a malicious LNK file. The LNK decrypts PowerShell that checks for analysis tools and virtual machines, profiles the host…
The U.S. Treasury reported that North Korean hackers used Xinbi Guarantee, an illicit marketplace that supplied escrow and transactional services to scam operators, money-laundering networks, and cybercrime syndicates. OFAC sanctioned Xinbi Guarantee and …
Chainalysis found that DPRK-linked actors laundered tens of millions of dollars stolen in the Bybit and WazirX hacks through Xinbi Guarantee's vendor network. Specialized “Black U” vendors substituted traceable stolen assets for less-tainted stablecoins s…
A live operator compromised an instrumented decoy workstation through a trojanized PyPI package and fake coding assignment, producing activity assessed as consistent with the DPRK-linked PolinRider campaign. The operator deployed JavaScript and Python pay…
ESTsecurity attributes a new malicious LNK operation targeting South Korean organizations to Kimsuky based on the group's established shortcut-based delivery and Korean business-document lures. The chain uses batch scripts, renamed Windows utilities, and …
SEAL handled 48 incidents from September 1–8, including DPRK intrusion losses totaling $400,000. It identified nine domains as infrastructure related to confirmed DPRK activity, several of which impersonated Microsoft Teams or Whereby services. The weekly…
GTIG observed at least one DPRK IT worker cluster registering LLM APIs in bulk through hijacked accounts to scale its operations. DPRK-linked clusters also used LLM prompts to profile aerospace and defense targets and generate fabricated resumes, job desc…
Kimsuky continues to target South Korean military, government, and public-sector organizations with tailored spearphishing designed for long-term espionage access. Its delivery methods include malicious LNK files disguised as documents, counterfeit softwa…
Kudelski Security and Sekoia map North Korea's offensive cyber capabilities as a distributed state system led principally by the GRIB and NIA, with frequently reorganized units conducting espionage, sabotage, ransomware, and financial theft. They divide t…