Gunra evolved from a Conti-derived ransomware variant first observed in April 2025 into a structured ransomware-as-a-service operation with Windows and Linux encryptors. Its affiliates exploit vulnerable or weakly secured VPN and firewall appliances, stea…
« Reports in 2026
593 reports
Researchers hired suspected Famous Chollima operatives into a controlled fake DeFi startup and monitored their behavior after onboarding. The workers used forged or stolen identities, mule banking details, remote-access software, AstrillVPN, AI services, …
North Korea combines nationwide network isolation, state-controlled application distribution, persistent device surveillance, cryptographic file restrictions, and physical enforcement to prevent citizens from accessing or sharing outside information. Andr…
BCA LTD, NorthScan, and ANY.RUN recruited DPRK-linked Famous Chollima IT workers into a controlled DeFi company and recorded their activity through monitored Windows sandboxes. The investigation exposed false-identity and facilitator arrangements, remote-…
Genians links Operation GitPower to Kimsuky, which uses spearphishing, malicious LNK files, obfuscated PowerShell, scheduled tasks, and Git repositories to collect system data and deploy encrypted AsyncRAT payloads. Infrastructure logs show the operators …
Genians links Operation GitPower to Kimsuky, which uses spearphishing, malicious LNK files, obfuscated PowerShell, scheduled tasks, and Git repositories to collect system data and deploy encrypted AsyncRAT payloads. Infrastructure logs show the operators …
Bybit filed a U.S. civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group over the February 2025 theft from the exchange. A preliminary injunction freezes identified stolen assets and prohibits their transfer or dissip…
FSI responders recovered a major guarantee insurer from a hands-on Gunra ransomware attack after finding that the malware reseeded C's `rand()` inside every key-generation iteration. The error reduced each nominal 256-bit ChaCha20 key to one repeated byte…
AhnLab linked recent Xctdoor distribution tracked as Larva-26005 to CRAT attacks against South Korean users dating to 2020, which other security firms attributed to Lazarus. Shared AppX installation paths, runtime code-obfuscation methods, and the earlier…
AhnLab linked recent Xctdoor distribution tracked as Larva-26005 to CRAT attacks against South Korean users dating to 2020, which other security firms attributed to Lazarus. Shared AppX installation paths, runtime code-obfuscation methods, and the earlier…
A Greece-based security researcher, Vangelis Stykas, spent 22 months inside North Korean hackers' command-and-control servers and found evidence that 1,640 companies across 57 countries were impacted by DPRK hacking operations, with 700–800 suffering "rea…
Two state-trained IT specialists were arrested in Wonsan in July 2026 for running a smishing and voice-phishing scheme that drained e-wallet funds from North Korea's wealthy donju market entrepreneurs. The pair sent malware-laden text messages impersonati…
CrowdStrike attributes the poisoning of 131 AI framework packages to the North Korea-linked STARDUST CHOLLIMA adversary, demonstrating an effort to compromise trusted components upstream in the developer ecosystem. Such poisoned dependencies can provide a…
DPRK-linked Contagious Interview operators embedded NullReceiver in the trojanized npm packages bianira-ui and fluid-type-ui. The technique retrieves an attacker's latest zero-value, zero-data Ethereum transaction and decodes a C2 IP address from the reci…
A newly surfaced version of North Korea’s SiliVaccine antivirus replaces the stolen Trend Micro engine found in 2018 with ClamAV signatures and Malheur-based behavioral clustering. Internal artifacts still point to suspected developer PGI, while the user-…