Bitrefill says a March 1, 2026 intrusion showed similarities to past DPRK Lazarus/Bluenoroff attacks on cryptocurrency companies, citing modus operandi, malware, on-chain tracing, and reused IP and email addresses. Initial access came from a compromised e…
« Reports in 2026
593 reports
Breakglass analyzed two samples from a Hungarian incident as evidence that Lazarus Group operated as a Medusa ransomware-as-a-service affiliate rather than only deploying DPRK-built ransomware. The TSMSISrv.dll loader is attributed to Lazarus-linked trade…
SpiderLabs describes a North Korea-linked remote IT worker attempt in which an organization hired a suspected operative who was detected and terminated within ten days. Cybereason XDR first flagged anomalous Entra ID activity when the new hire logged in f…
IIJ analyzed malware delivered by an LNK file uploaded from Korea and found extensive overlap with a Kimsuky campaign previously reported by AhnLab ASEC. When opened, the LNK extracted XOR-decoded components into C:\PerfLog, deployed www.ps1 and 17.vbs, a…
kmsec.uk reports that Contagious Trader targets cryptocurrency users through malicious GitHub trading bot repositories and npm packages themed around Polymarket, Kalshi, Solana, Raydium, copy trading, and related market activity. The author attributes the…
ANY.RUN promoted an expert panel on 2026 enterprise security risks that included research into a real-world Lazarus Group infiltration case. The preserved source text frames the discussion around AI-driven phishing, modern attacks that blend into business…
NTT Security Japan analyzed StoatWaffle, a newly adopted Node.js malware used by WaterPlum, which the article describes as a North Korea-related group operating the Contagious Interview campaign. The attack uses a blockchain-themed decoy repository whose …
NTT Security Japan analyzed StoatWaffle, a newly observed Node.js malware used by WaterPlum Team 8 in the North Korea-linked Contagious Interview campaign. The attack uses a blockchain-themed malicious VSCode repository whose tasks.json runs on folder ope…
SectorA activity in February 2026 centered on fake recruitment lures against software developers in cryptocurrency, finance, and IT, using trusted platforms such as Vercel, npm, and PyPI to distribute malware. NSHC associated the activity with BeaverTail,…
A Node.js stage-one dropper attributed in the excerpt to Lazarus Group's TraderTraitor sub-cluster uses Solana transaction memos as a dead-drop resolver for rotating C2 infrastructure. The malware queries a specific Solana wallet through the public mainne…
Nisos identified a suspected DPRK IT worker applying for a remote Lead AI Architect role by combining pre-employment OSINT with targeted interview questions. The applicant allegedly used stolen personally identifiable information, a newly created Gmail ac…
Genians Security Center analyzed a Konni APT campaign that used North Korea-themed spear-phishing to gain initial access. The lure impersonated a notice appointing the recipient as a North Korean human-rights lecturer and delivered an archive containing a…
Genians Security Center links the activity to the Konni APT group and describes a spear-phishing campaign that used a North Korean human-rights lecturer appointment lure to gain initial access. Victims were induced to run a malicious LNK file that launche…
KMSEC found two npm packages published by jaime9008 distributing an obfuscated loader for PylangGhost, a RAT the excerpt says Cisco Talos attributed to FAMOUS CHOLLIMA. Malicious versions of react-refresh-update and @jaime9008/math-service used runtime.js…
Breakglass Intelligence analyzed Gunra ransomware's Linux variant, an 84KB Conti-derived ELF expanded into x86-64, i386, ARM, and Windows builds for enterprise and multi-architecture targeting. The Linux build encrypts files with ChaCha20 and RSA-4096, bu…