Breakglass Intelligence analyzed Gunra ransomware's Linux variant, an 84KB Conti-derived ELF expanded into x86-64, i386, ARM, and Windows builds for enterprise and multi-architecture targeting. The Linux build encrypts files with ChaCha20 and RSA-4096, bu…
« Reports in 2026
594 reports
Kimsuky is reported deploying a five-stage GrimResource loader that begins with a Microsoft Management Console .msc file and ends with roughly 1MB of x86 shellcode executed in memory. The plugin.msc sample embeds an XSL Transform payload in the MMC XML St…
Two samples submitted by the same Hungarian incident responder are presented as linking Lazarus Group to Medusa ransomware activity: gaze.exe, a Medusa encryptor, and TSMSISrv.dll, a Lazarus-detected DLL sideloading loader. The ransomware's XOR-decoded co…
Chainalysis reported that OFAC sanctioned six individuals and two entities tied to DPRK IT worker fraud schemes that generated nearly $800 million in 2024 for North Korea’s weapons programs. The schemes used fraudulent documents, stolen identities, and fa…
OFAC sanctioned six individuals and two entities involved in DPRK government-orchestrated IT worker schemes that defrauded U.S. businesses and generated revenue for North Korea’s WMD programs, including nearly $800 million in 2024. The workers used fraudu…
Microsoft observed Contagious Interview using fake developer recruitment workflows to compromise software developers at enterprise solution providers and media and communications firms. The campaign persuaded victims to clone or execute malicious npm pack…
AhnLab’s February 2026 APT trends report highlighted North Korea-linked activity involving Lazarus, BlueNoroff, UNC1069, and TA-RedAnt/APT37 alongside other global APT operations. The Lazarus section said the group used Medusa ransomware against U.S. heal…
Cyble profiles WageMole as a North Korean state-sponsored group that gains access to Western organizations by placing operatives into remote jobs under fabricated identities. The activity is tied to Operation Contagious Interview, where stolen personal da…
An email sent from a North Korean @star-co.net.kp address exposed how DPRK software developers market domestically built products to overseas commercial partners, distinct from the better-known fraudulent IT worker hiring schemes. The headers showed origi…
SerapHim analyzes the StegaBin wave of the Contagious Interview supply-chain campaign, attributing it to Famous Chollima under the Lazarus Group umbrella with high confidence. The wave used 26 typosquatted npm packages across separate accounts to target s…
Abstract Security tracks continued Contagious Interview abuse of VS Code and Cursor automated tasks to deploy WeaselStore malware, including the Windows PylangGhost and macOS GolangGhost variants. The Windows chain uses a PowerShell script posing as an NV…
Logpresso analyzed 1,045,645 infostealer telemetry records collected since 2024 against 1,879 known DPRK remote IT worker account patterns to study fraudulent remote employment operations. The research correlated email accounts, IP addresses, hardware IDs…
Google Cloud’s H1 2026 Threat Horizons report includes a DPRK-relevant case where North Korean actors used living-off-the-cloud techniques after social engineering created a personal-to-corporate access path. The actors bypassed traditional network perime…
OpenSourceMalware attributes the PolinRider campaign to DPRK activity and says the actor implanted obfuscated JavaScript payloads in 675 public GitHub repositories across 352 owners by March 8, 2026. The injected code was appended after legitimate content…
OpenSourceMalware reports that DPRK threat actors compromised four Neutralinojs GitHub organization repositories in a 132-second automated burst on March 2, 2026. The attacker used the alphagamer7 account to force-push backdated malicious commits, spoof m…