BBC Korea obtained computer recordings and internal messenger logs that show how North Korean IT workers are managed as part of an organized fake-employment operation rather than as isolated freelancers. The material and expert review describe layered rol…
« Reports in 2026
508 reports
OpenSourceMalware highlights Lazarus Group software supply chain techniques including malicious-version “sandwiching,” reuse of Aptos/Tron/BSC blockchain infrastructure for mutable C2, and embedded campaign-tracking strings in payloads. The episode cites …
IIJ-SECT observed a May 2026 Kimsuky-linked KimJongRAT campaign that redirected targets from emailed shortened links to malicious GitHub Releases ZIP files containing LNK payloads. The infection chain used mshta, obfuscated VBScript, Google Drive-hosted e…
Moonlock Lab identified a macOS cross-platform RAT masquerading as MicrosoftSystem64, with a JavaScript payload bundled inside a Mach-O binary through `__NODE_SEA_BLOB`. The malware provides full surveillance and remote-control capabilities, including ada…
North Korean APT activity in Q2 2026 combined cryptocurrency theft, supply-chain compromise, cloud-focused intrusions, and strategic espionage. Lazarus targeted cryptocurrency exchanges, DeFi platforms, software vendors, defense contractors, and technolog…
Darktrace observed a recurring intrusion pattern in which ClickFix-style social engineering led macOS users into execution, followed by AppleScript or other native scripting and sustained outbound signaling. The use case is explicitly tied to activity Mic…
Sapphire Sleet compromised the `ehindero` npm maintainer account and injected the malicious `[email protected]` dependency into 144 Mastra AI npm packages during an 88-minute window on June 17, 2026. The postinstall hook executed an obfuscated JavaScrip…
The malicious npm packages `chalk-ultra` and `vitest-cli` execute a hidden downloader that steals developer credentials, source code, browser data, and cryptocurrency-wallet information. The payload can replace Chrome's MetaMask extension with a persisten…
A North Korea-linked Lazarus subgroup targeted financial institutions and cryptocurrency organizations with a multi-stage malware framework built around DPAPILoader, RemotePELoader, and the in-memory RemotePE RAT. The toolset uses Windows DPAPI for enviro…
Passive OSINT collection outside the DPRK embassy in London identified ordinary wireless infrastructure and endpoint signals rather than malicious activity. The observations suggest the site has used BT, Virgin Media, and previously TalkTalk connectivity,…
SentinelLABS analyzed macOS.Gaslight, a Rust-based macOS implant and infostealer assessed with high confidence as part of DPRK-aligned macOS activity. The malware uses Telegram Bot API polling for C2, AES-GCM encryption over certificate-pinned TLS, and ru…
Kimsuky's DEEP#DRIVE initial-access chain used phishing-delivered LNK files disguised as documents to launch hidden PowerShell, retrieve hosted scripts and payloads, and open a decoy PDF. The emulation reproduces scheduled-task persistence and payload exe…
Melted in Hex reverses PolinRider, a DPRK/Lazarus-attributed npm supply-chain loader hidden in the functional packages tailwind-color-shades and safe-validate. The loader executes on import, resolves encrypted stages through TRON, Aptos, and Binance Smart…
A developer reported obfuscated JavaScript hidden in `tailwind.config.js` and another backend file across three repositories, followed by unknown Node processes in local and production environments and Git commits made under the author's name. Sandbox ana…
Lazarus is presented as a North Korean state-backed umbrella of related teams that blends espionage, disruptive attacks, cryptocurrency theft, supply chain compromise, and IT-worker infiltration. The article highlights major attributed incidents including…