« 2025 »

778 reports

2025-09-08 • Zscaler

Zscaler ThreatLabz details recent APT37 activity against Windows systems, linking the North Korean-aligned actor to Rustonotto, Chinotto, and FadeStealer. The campaigns use Windows shortcut files and CHM help files as initial delivery vectors, including a…

#Chinotto #APT37 #Rustonotto #T1059.003 #T1041 #T1113 #T1071.001 #T1056.001 #T1204.001 #T1059.007 #T1566.001 #T1547.001 #T1053.005 #T1132.001 #T1123 #T1036.004 #T1218.005 #T1025 #T1055.013 #T1036.003 #T1560.001
2025-09-04 • Chollima Group

Chollima Group links the Hailong Jin and Lian Hung personas to suspected North Korean IT worker activity, including GitHub accounts tied to Unity/game development, blockchain work, and overlap with strings seen in Moonstone Sleet's DeTankZone research. Le…

#BABYLONGROUP
2025-08-31 • NKInternet

NK Internet examined an Arirang 182 North Korean feature phone, a rugged IP68-rated handset with a 2.4-inch display, removable battery/SIM compartment, and domestic support references such as the 999 subscription number. The device could be switched to En…

2025-08-29 • ENKI

A phishing email sent to a South Korean energy-company domain delivered a RAR attachment containing a .NET executable disguised as an air cargo waybill. The executable was identified as a PureCrypter first-stage loader that contacted 158.247.250[.]251 for…

#Kimsuky #T1082 #T1059.003 #T1140 #T1005 #T1041 #T1115 #T1204.002 #T1071 #T1057 #T1566.001 #T1547.001 #T1059.001 #T1132.001 #T1497.001 #T1622 #T1027.002 #T1573.001 #T1055.012 #T1095 #T1047 #T1134.001 #T1665 #T1055.002 #T1070.010 #T1055.003 #T1027.014
2025-08-29 • Seqrite

Seqrite links Operation HanKook Phantom to APT37, a North Korean state-backed espionage actor also known as InkySquid, ScarCruft, Reaper, Group123, TEMP.Reaper, and Ricochet Chollima. The campaign used a National Intelligence Research Society newsletter d…

#APT37 #RokRAT #LNK #T1102.002 #T1027.013 #T1082 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1083 #T1204.001 #T1204.002 #T1566.001 #T1547.001 #T1053.005 #T1059.001 #T1123 #T1087.001 #T1056.002 #T1574.001 #T1217 #T1027.009 #T1529 #T1055.009 #T1055.001