« 2025 »

778 reports

2025-09-30 • Okta

Okta Threat Intelligence found that DPRK IT-worker operations now affect remote-hiring organizations far beyond U.S. big technology companies. The investigation tracked more than 130 facilitator and worker identities tied to over 6,500 initial job intervi…

#ITWorker
2025-09-28 • Sandfly Security

Sandfly Security released a detection script for a Linux Loadable Kernel Module rootkit described in a Phrack data dump attributed in the source to a threat actor purportedly from North Korea. The tool checks for hidden kernel modules that disappear from …

#Kimsuky #APTDown
2025-09-26 • Piolink

PIOLINK links recent APT37 activity to a shared C2 infrastructure used to operate Rustonotto, Chinotto, and FadeStealer against targets connected to North Korea policy, human rights, and South Korean interests. Initial access uses Windows shortcut files a…

#APT37 #LNK
2025-09-25 • ESET

ESET describes DeceptiveDevelopment as a North Korea-aligned financially motivated group active since at least 2023 and tightly connected to WageMole, the activity cluster associated with North Korean IT workers. Operators pose as recruiters on platforms …

#BeaverTail #InvisibleFerret #ClickFix #DeceptiveDevelopment #Tropidoor #Tsunami #T1071.001 #T1497 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.001 #T1059 #T1585.001 #T1105 #T1055 #T1078 #T1589 #T1586
2025-09-23 • Barracuda

Barracuda profiles Lazarus Group as a DPRK state-linked cybercrime and espionage ecosystem operating under the Reconnaissance General Bureau rather than a single monolithic actor. The article distinguishes major clusters including TEMP.Hermit, Kimsuky/APT…

#Lazarus
2025-09-22 • Ahnlab

AhnLab tracks Larva-25004 as a Kimsuky-linked operation active since at least August 2023 against South Korean public enterprises, defense industry organizations, research institutes, and at least one job seeker of unknown nationality. The group uses spea…

#Kimsuky #CJOliveNetworks #Larva-25004