« Reports in 2026

594 reports

2026-03-12 • Break Glass Intelligence

Breakglass Intelligence analyzed Gunra ransomware's Linux variant, an 84KB Conti-derived ELF expanded into x86-64, i386, ARM, and Windows builds for enterprise and multi-architecture targeting. The Linux build encrypts files with ChaCha20 and RSA-4096, bu…

#Ransomware #YARA #Gunra #T1082 #T1083 #T1059.004 #T1027 #T1486 #T1491.001 #T1070.002 #T1548 #T1053.003 #T1556.003 #T1037
2026-03-12 • Break Glass Intelligence

Two samples submitted by the same Hungarian incident responder are presented as linking Lazarus Group to Medusa ransomware activity: gaze.exe, a Medusa encryptor, and TSMSISrv.dll, a Lazarus-detected DLL sideloading loader. The ransomware's XOR-decoded co…

#Ransomware #Lazarus #Medusa #T1082 #T1555 #T1059.001 #T1036.005 #T1574.002 #T1562.001 #T1490 #T1486 #T1547.014 #T1129 #T1622 #T1135 #T1027.002 #T1546.015 #T1489
2026-03-10 • NKInternet

An email sent from a North Korean @star-co.net.kp address exposed how DPRK software developers market domestically built products to overseas commercial partners, distinct from the better-known fraudulent IT worker hiring schemes. The headers showed origi…

2026-03-09 • Google

Google Cloud’s H1 2026 Threat Horizons report includes a DPRK-relevant case where North Korean actors used living-off-the-cloud techniques after social engineering created a personal-to-corporate access path. The actors bypassed traditional network perime…

#UNC4899 #UNC5267