« Reports in 2026

593 reports

2026-03-29 • Swim Sec

North Korea-linked groups remained highly active in Q1 2026, with Lazarus, BlueNoroff, Andariel, Famous Chollima/UNC1069, ScarCruft/APT37, Kimsuky, and Konni tied to financially motivated and espionage activity. The DPRK-relevant campaigns centered on fak…

#Trend
2026-03-23 • Secure Works

NICKEL ALLEY is described as a North Korean government-linked threat group focused on espionage and surveillance. The group targets technology-sector professionals by advertising fake job opportunities and moving victims through a fraudulent interview pro…

#NickelAlley
2026-03-19 • Ahnlab

AhnLab observed February 2026 APT activity targeting South Korea, with spear phishing as the dominant delivery method and LNK files the most common attachment type. One LNK chain contacted an external URL through PowerShell, copied curl.exe under another …

#Phishing #LNK
2026-03-18 • Flare

Flare Research and IBM X-Force describe North Korean IT worker operations that use false personas, freelance platforms, and full-time remote roles to generate revenue for the DPRK state and sometimes enable espionage, theft, extortion, or cryptocurrency t…

#ITWorker