#DangerousPassword
Incident/Operation
DangerousPassword is a North Korean campaign active since around 2019 that initially targeted cryptocurrency exchanges and later expanded to developers and financial organizations across Windows, macOS, and Linux environments. Operators approach employees through LinkedIn, sometimes from hijacked legitimate accounts, and pressure them to open archives or execute files presented as recruitment material; early waves repeatedly used a malicious shortcut named Password.txt.lnk, while later activity adopted virtual disks, OneNote files, and other delivery formats. The campaign is associated with North Korea's Reconnaissance General Bureau, and a 2026 operation also compromised the axios software supply chain through elaborate impersonation and social engineering.
-
11
Tagged Reports
-
5
Unique Authors
-
2,333
Active Days