Recorded Future links PurpleDelta to a state-directed network of North Korean IT workers that used at least 22 fabricated personas to apply to more than 1,100 companies and likely obtained employment at ten or more organizations. Operators combined illici…
« Reports in 2026
593 reports
Lazarus Group reportedly exploited the Windows `afd.sys` privilege-escalation flaw CVE-2026-68820 as a zero-day during an Operation Dream Job campaign targeting defense and aerospace organizations in four countries. Fake Enveil recruitment material delive…
North Korea's PolinRider campaign has expanded from more than 300 affected GitHub owners in March 2026 to over 2,000 owners and 4,000 compromised repositories by July. It infects developers through fake Contagious Interview coding tests, trojanized packag…
An on-chain researcher documented a suspected DPRK IT worker who applied as "Ming Cheng" using the hodlwarden persona and supplied inconsistent employment and location details. The researcher linked the hodlwarden GitHub account to the Contagious Trader c…
Moonlock Lab analyzed an active Contagious Interview chain targeting macOS users with a fake Git helper shell script that downloads a Node.js runner and an obfuscated OtterCookie payload. The payload steals browser passwords and Keychain data, scans files…
A recovered archive tied to a DPRK-affiliated device documents an eleven-stage IT-worker fraud lifecycle: selecting and buying American identities, validating and altering documents, building U.S.-based infrastructure, applying at scale, defeating intervi…
A fake Web3 recruiter compromised a cryptocurrency employee through a Google Apps Script assessment that delivered a signed ClickOnce package, two credential stealers, and a persistent Go RAT with hVNC. Exact overlap in an SSL.com signing certificate and …
A suspected North Korean IT worker applying to Ump Labs used questionable names and locations but demonstrated credible blockchain-engineering and smart-contract security knowledge during an undercover interview. Researchers linked his profiles, email add…
The Wall Street Journal used leaked browser histories, emails, calendars, screen recordings, interviews, and previously unseen videos to trace a North Korean remote-worker cell that infiltrated at least eight U.S. companies within months. Thousands of DPR…
Kudelski Security linked a DPRK-associated operator known as Bismarck to gambling administration infrastructure and IP addresses that overlap earlier FakeCalls research. A separate fake IT worker manager held credentials for two systems later associated w…
North Korea is estimated to have stolen at least $2.8 billion in virtual assets between January 2024 and September 2025, with proceeds moving through decentralised services, third-party launderers, OTC and peer-to-peer traders, money mules and guarantee m…
Lazarus expanded Operation Dream Job against defense, aerospace, and aviation organizations by combining fraudulent recruitment lures with trojanized PDF viewers and impersonation websites. The campaign exploited the Windows AFD.sys zero-day CVE-2026-6882…
North Korean remote IT workers use stolen identities, fabricated GitHub histories, interview stand-ins, deepfake tools, domestic laptop farms, and hardware KVM devices to obtain trusted access to foreign companies. Microsoft and Secureworks track overlapp…
The FBI is investigating a North Korean remote IT worker recently discovered working for an unidentified U.S. federal agency, although the worker’s role, duration of access, and possible exposure of sensitive data remain unknown. The case extends a fraudu…
Six npm packages delivered an identical JavaScript loader, including three hijacked legitimate packages and three packages published with the malware already embedded. The loader used an Ethereum transaction as a dead drop, decoding command-and-control IP…