Attackers hijacked the jasonsaayman npm account and published malicious [email protected] and [email protected], adding [email protected] solely to run a postinstall dropper. The package contacted sfrclak[.]com:8000 and installed platform-specific RAT payloads …
« Reports in 2026
593 reports
HAURI analyzed a Korean campaign that disguised malware as a required integrated security installer used for banking and public-sector websites, with the archive mimicking Veraport by using a similar filename and normal-looking installation flow. The infe…
A 60 Minutes Australia investigation reported that North Korean operatives are seeking remote IT roles at Australian and other technology companies using false identities, fake resumes, and online interview deception. The scheme is described as both sanct…
North Korea-linked groups remained highly active in Q1 2026, with Lazarus, BlueNoroff, Andariel, Famous Chollima/UNC1069, ScarCruft/APT37, Kimsuky, and Konni tied to financially motivated and espionage activity. The DPRK-relevant campaigns centered on fak…
38 North focuses on how DPRK-linked actors convert stolen cryptocurrency into usable funds after hacks and laundering. The article cites estimates that DPRK stole about $3 billion in 58 cyberattacks from 2017 to 2023, plus the Lazarus Group's approximatel…
eSentire TRU detected EtherRAT in a retail customer environment in March 2026 and notes that Sysdig has linked the Node.js backdoor to a North Korean APT through overlaps with Contagious Interview TTPs. The observed intrusion used ClickFix to run pcalua.e…
Mandiant’s M-Trends 2026 reported that North Korean IT worker incidents showed a median dwell time of 122 days in 2025, matching the persistence observed in cyber espionage cases. The broader incident data shows attackers increasingly exploiting gaps in i…
Kudelski Security identified four interconnected private networks that it assesses with moderate confidence as development infrastructure supporting DPRK fake IT worker operations. The environment contains AI, NPM, DevOps, CI/CD, source-control, collabora…
Sophos CTU reports that NICKEL ALLEY, a North Korean government-linked group, continued Contagious Interview operations against technology professionals through fake companies, fake jobs, malicious GitHub repositories, and developer assessment lures. Sinc…
NICKEL ALLEY is described as a North Korean government-linked threat group focused on espionage and surveillance. The group targets technology-sector professionals by advertising fake job opportunities and moving victims through a fraudulent interview pro…
The U.S. Attorney's Office for the Southern District of Georgia said Alexander Paul Travis, Jason Salazar, and Audricus Phagnasay were sentenced after pleading guilty to a wire-fraud conspiracy that enabled overseas IT workers to use U.S. identities for r…
Cyble says Bitrefill attributed a March 1, 2026 intrusion to actors linked to Lazarus Group, citing malware similarities, reused IP addresses, email patterns, and blockchain tracing. The attackers allegedly entered through a compromised employee laptop, u…
A 1ns0mn1h4ck talk describes an operation that infiltrated a cell of North Korean IT workers seeking remote employment for the DPRK. The speakers say the cell targeted Latin American financial and cryptocurrency sectors and attribute the activity to Famou…
AhnLab observed February 2026 APT activity targeting South Korea, with spear phishing as the dominant delivery method and LNK files the most common attachment type. One LNK chain contacted an external URL through PowerShell, copied curl.exe under another …
Flare Research and IBM X-Force describe North Korean IT worker operations that use false personas, freelance platforms, and full-time remote roles to generate revenue for the DPRK state and sometimes enable espionage, theft, extortion, or cryptocurrency t…