AFX attributes its July 2026 custody-bridge theft to UNC4899 / TraderTraitor after a developer cloned a malicious DEX repository offered through a fake job approach. A modified Git post-checkout hook launched the initial payload, and the attacker later pe…
« Reports in 2026
593 reports
North Korean IT workers use forged or borrowed identities, third-party facilitators, and concealed remote-access arrangements to obtain employment and remit income to state-linked agencies supporting prohibited weapons programs. The workers can also creat…
North Korean IT workers use forged identities and third-country proxies to obtain remote jobs and remit salaries to DPRK agencies that support nuclear and ballistic missile programs. The joint alert says they may pose insider risks involving data exfiltra…
DPRK's PolinRider campaign automatically poisoned legitimate npm packages and Go modules after compromising developer machines, rather than deliberately selecting high-value packages for account takeover. OpenSourceMalware linked 20 analyzed packages thro…
North Korean actor MIDNIGHT NEPTUNE, formerly UNC1069, used a socially compromised maintainer account to introduce a malicious dependency into `axios`, deploying the WAVESHAPER.V2 backdoor and potentially exposing a package ecosystem with more than 100 mi…
PLAINBIT reconstructed a watering-hole intrusion in which a compromised trusted website exploited a vulnerable third-party security component and installed DLL backdoors without requiring a user to launch a file. One chain modified SageThumbs-related shel…
S2W analyzed three malware clusters targeting South Korea that combine legitimate-process abuse, DLL side-loading, encrypted payload staging, and manual PE mapping. Two chains deploy SIGNBT v0.0.1 or v1.2 from service-registry blobs or embedded containers…
South Korean security authorities warn that state-sponsored hacking groups are targeting Korean individuals and companies through phishing emails disguised as resumes, recruitment proposals, donations, or investment materials. The attackers also compromis…
State-sponsored attackers compromised legitimate South Korean websites and inserted exploit code targeting vulnerabilities in locally deployed security software, enabling drive-by malware installation. The recovered chains used ChaCha20 or AES-CBC-128 enc…
A state-backed group exploited vulnerabilities in South Korean financial security software through watering-hole and spear-phishing attacks, installing Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE) backdoors. A separate intrusion path used the same vul…
A state-sponsored threat group exploited vulnerabilities in Korean financial security software from 2025 through the first half of 2026, using watering holes and spear phishing to install Struggle (SIGNBT 3.0) and Brandoor (COPPERHEDGE) backdoors. AhnLab …
A search-driven malvertising chain displayed a fake macOS update and used ClickFix instructions to make victims paste a Node.js backdoor command into Terminal. The implant retrieved rotating C2 configuration from Ethereum smart contracts, executed JavaScr…
North Korean actors linked to the Lazarus ecosystem have shifted from destructive and SWIFT-focused operations toward large cryptocurrency thefts that target signing authority, employees, wallet providers, and operational infrastructure. The article highl…
DPRK-aligned operators continued using supply-chain compromise, fraudulent job-interview repositories, cryptocurrency theft, and overseas IT-worker infiltration to generate state revenue. Trend Micro says BlueNoroff compromised the Axios maintainer’s acco…
Amazon Threat Intelligence attributes the typo-crypto, debug, chalk, and axios NPM compromises with medium confidence to a DPRK-linked actor tracked under names including SAPPHIRE SLEET, STARDUST CHOLLIMA, BlueNoroff, CageyChameleon, and Alluring Pisces. …