Two malicious beta releases in the legitimate `@joyfill` npm scope executed an obfuscated loader when applications imported their production bundles. The loader resolved encrypted payloads through two successive Tron-to-BSC transaction chains, selected C2…
« Reports in 2026
593 reports
Two Joyfill npm prereleases published on 2026-07-28 contained an obfuscated DEV#POPPER-family RAT that executed when applications imported the packages, bypassing protections focused on npm install scripts. The implant obtained rotating command-and-contro…
WhoisXML API analyzed infrastructure from an APT37 campaign that delivered the Python-based NarwhalRAT through spear-phishing messages and malicious LNK files. The malware supports keylogging, screen capture, USB collection, and remote command execution, …
Malicious prerelease builds of `@joyfill/components` and `@joyfill/layouts` executed an obfuscated Node.js loader when imported, bypassing protections focused on npm installation scripts. The implant used blockchain transactions to resolve later stages, d…
Two Joyfill beta packages contained an import-time JavaScript implant that used Tron, Aptos, and BNB Smart Chain transactions to resolve mutable payloads. The recovered chain delivered a DEV#POPPER Node.js RAT capable of remote command execution, file tra…
Historical WHOIS records, shared DNS infrastructure, exposed documents, product overlap, and linked personas place Hato Tsusin in the same DPRK-connected commercial network as Glocom and Future Tech Group. Glocom was identified by a UN Panel of Experts as…
Compromise of AFX Trade's off-chain validator signing system allowed five signatures to authorize a fraudulent withdrawal of approximately $24.15 million in USDC from its Arbitrum bridge on July 22, 2026. The attacker bridged the assets to Ethereum, conve…
An attacker stole assets from AFX's custody bridge after compromising a developer through a malicious repository shared over Telegram. The intrusion spread into AFX's JFrog environment, where a malicious Groovy plugin and modified system components mainta…
Google Threat Intelligence Group’s unified actor-naming system will assign North Korea-attributed threat clusters the category word NEPTUNE as the second element of a two-word cryptonym. The first word will uniquely identify the tracked actor, while the s…
BlueNoroff used compromised Telegram accounts belonging to trusted industry contacts to direct cryptocurrency and Web3 personnel into operator-controlled Zoom and Microsoft Teams lures. The kit profiled browser wallets, relayed victims' webcams, displayed…
JUMPSEC recovered source code and malware from a BlueNoroff platform that impersonates Zoom and Microsoft Teams meetings, profiles cryptocurrency wallets, and delivers ClickFix payloads to Windows and macOS victims. Operators approached targets through hi…
Discharged veterans of a North Korean military intelligence cyber unit allegedly recruited elite university-trained IT personnel to breach the Chosun Central Bank and Foreign Trade Bank. The group reportedly diverted state trade funds in small increments,…
AhnLab observed June 2026 domestic APT activity delivered primarily through spear-phishing emails and malicious LNK files, and the source categorizes the analysis under Kimsuky. The documented chains used PowerShell, AutoIt, HTA files, GitHub-hosted paylo…
AhnLab's June 2026 monitoring found that APT attacks in South Korea predominantly began with work-themed spear phishing and malicious LNK files, and the source categorizes the activity under Kimsuky. The observed chains used PowerShell, AutoIt, curl, HTA …
Kimsuky is targeting foreign-affairs personnel with spearphishing lures that execute malicious LNK files and install PebbleDash, PrxClient, RDP tooling, UAC bypass utilities, and a keylogger. PebbleDash provides extensive remote command, file-transfer, pr…