Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto
2026-08-21 • Zscaler •
DPRK espionage groups Konni and Kimsuky have expanded into cryptocurrency-focused operations using distinct but increasingly sophisticated infection chains. Konni targeted crypto professionals with disguised AppleScript files, fake macOS password dialogs, TCC database manipulation, persistent Node.js malware, FileRATClient, and an EggShell implant. Kimsuky's TokenPhantom campaign promoted the fake Tralert FX trading platform and delivered a customized Xeno RAT through an Electron application, PowerShell stages, GitLab infrastructure, and reflective in-memory loading. The slides report more than 250 victim IPs across 28 countries and identify AI-assisted development in both actors' tooling.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| URL | http://161.97.113.34:3001/api/t… | 2026-05-14 | 2026-08-25 |
| IPv4 | 161.97.113.34 | 2026-05-14 | 2026-08-25 |