« Reports in 2026

593 reports

2026-03-18 • Bitrefill

Bitrefill says a March 1, 2026 intrusion showed similarities to past DPRK Lazarus/Bluenoroff attacks on cryptocurrency companies, citing modus operandi, malware, on-chain tracing, and reused IP and email addresses. Initial access came from a compromised e…

#Bluenoroff #Bitrefill
2026-03-17 • Break Glass Intelligence

Breakglass analyzed two samples from a Hungarian incident as evidence that Lazarus Group operated as a Medusa ransomware-as-a-service affiliate rather than only deploying DPRK-built ransomware. The TSMSISrv.dll loader is attributed to Lazarus-linked trade…

#Ransomware #Lazarus #Medusa #T1082 #T1555 #T1059.001 #T1036.005 #T1574.002 #T1562.001 #T1490 #T1486 #T1547.014 #T1129 #T1622 #T1135 #T1027.002 #T1546.015 #T1489
2026-03-16 • Break Glass Intelligence

A Node.js stage-one dropper attributed in the excerpt to Lazarus Group's TraderTraitor sub-cluster uses Solana transaction memos as a dead-drop resolver for rotating C2 infrastructure. The malware queries a specific Solana wallet through the public mainne…

#TraderTraitor #T1082 #T1041 #T1059.007 #T1036 #T1027 #T1583.003 #T1102.001 #T1195.001 #T1622 #T1008 #T1070.009 #T1573.001 #T1571 #T1497.003
2026-03-15 • NISOS

Nisos identified a suspected DPRK IT worker applying for a remote Lead AI Architect role by combining pre-employment OSINT with targeted interview questions. The applicant allegedly used stolen personally identifiable information, a newly created Gmail ac…

#ITWorker
2026-03-12 • Break Glass Intelligence

Breakglass Intelligence analyzed Gunra ransomware's Linux variant, an 84KB Conti-derived ELF expanded into x86-64, i386, ARM, and Windows builds for enterprise and multi-architecture targeting. The Linux build encrypts files with ChaCha20 and RSA-4096, bu…

#Ransomware #YARA #Gunra #T1082 #T1083 #T1059.004 #T1027 #T1486 #T1491.001 #T1070.002 #T1548 #T1053.003 #T1556.003 #T1037