Genians attributes 13 malicious LNK variants collected in August 2026 to Kimsuky’s Operation GitPower, citing matching LNK fingerprints, a shared custom decoder, GitHub PAT-authenticated delivery, and disguised scheduled tasks. The variants execute obfusc…
« Reports in 2026
593 reports
Genians attributes 13 malicious LNK variants collected in August 2026 to Kimsuky’s Operation GitPower, citing matching LNK fingerprints, a shared custom decoder, GitHub PAT-authenticated delivery, and disguised scheduled tasks. The variants execute obfusc…
Rapid7 identified a previously undocumented Linux espionage toolkit targeting South Korean media and automotive organizations and attributed the activity with medium confidence to DPRK APT operators. The framework combines a modified HAProxy implant calle…
Jamf identified 14 trojanized macOS DMG and PKG samples tied to the DPRK-attributed Contagious Interview campaign, extending its delivery methods beyond fake coding tests, Visual Studio Code task files, and Git hooks. The unsigned installers launched legi…
An attacker using a BindsNET collaborator's credentials hid a malicious Visual Studio Code folder-open task inside a forged merge commit and force-pushed it across 20 branches. A routine Dependabot merge later carried the injected files into the master br…
Attackers used compromised collaborator credentials to force-push a forged merge commit across 20 BindsNET branches, eventually introducing it into `master` through a routine Dependabot merge. A hidden Visual Studio Code task automatically ran obfuscated …
Kimsuky-linked operators distributed a malicious LNK disguised as a seafood ingredient purchase-review request to South Korean users. Execution displayed a legitimate HWP decoy while extracting PowerShell and JavaScript components, establishing a schedule…
Kimsuky-linked operators distributed a malicious LNK disguised as a seafood ingredient purchase-review request to South Korean users. Execution displayed a legitimate HWP decoy while extracting PowerShell and JavaScript components, establishing a schedule…
Security Alliance handled 45 incidents between August 25 and 31, including a DPRK intrusion associated with $1.5 million in reported losses. The organization identified six domains observed that week as confirmed DPRK/UNC1069 infrastructure, several of wh…
SafeDep uncovered an npm dependency chain in which `ioredis-xyz` silently resolved `redis-type-xyz` and then the malicious `ulid-xyz` package, whose postinstall hook launched a cross-platform remote access trojan. The implant persisted as MicrosoftSystem6…
Arkham identified Lazarus-linked wallets selling more than $30 million in bitcoin through Hyperliquid over three weeks. The proceeds were converted into ether and solana and then transferred to Kraken, LBank, and KuCoin, although CoinDesk could not determ…
LNK shortcut files were the leading delivery format among APT attacks AhnLab detected against South Korean targets in July 2026. The documented infection chains used PowerShell, AutoIt, HTA files, scheduled tasks, DLL side-loading, GitHub, Google Drive, D…
Spear-phishing was the predominant delivery method observed against South Korean targets in July 2026, with malicious LNK files accounting for the largest share. The documented chains used PowerShell, AutoIt, HTA files, scheduled tasks, DLL side-loading, …
Huntress investigated five people employed across healthcare, financial services, IT, sales and marketing, and medicine who were assessed as likely DPRK remote workers using fraudulent or stolen identities. Correlated evidence included Astrill VPN and IPR…
PolinRider operators compromised a legitimate developer's GitHub identity and repeatedly used it to distribute DPRK-attributed NullReceiver malware through `fetch-page-assets` and other npm packages. Although npm removed version 1.2.9, the underlying `.vs…