« 2025 »

778 reports

2025-07-15 • Ahnlab

AhnLab observed June 2025 APT activity in South Korea dominated by spear phishing, with LNK-based attacks the largest share and HWP-based attacks increasing from the previous month. The LNK cases embedded malicious PowerShell in shortcut files, unpacked C…

#LNK
2025-07-15 • Socket

Socket reports that North Korean Contagious Interview operators expanded their software supply-chain activity with 67 malicious npm packages, including 28 tied to the newly identified XORIndex loader and 39 new HexEval packages. XORIndex collects host met…

#NPM #ContagiousInterview #XORIndex #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2025-07-14 • Poly Swarm

North Korea-linked operators, assessed in the excerpt as likely Stardust Chollima, used NimDoor macOS malware against Web3 and cryptocurrency organizations. The intrusion chain began with Telegram social engineering and fake Zoom meeting lures, then deliv…

#StardustChollima #NimDoor
2025-07-11 • Moonlock

Moonlock summarizes SentinelOne research on North Korean fake-interview malware targeting Web3, crypto, and blockchain businesses through Zoom-themed social engineering. Victims are lured into interviews and instructed to run a fake Zoom SDK update script…

#NimDoor
2025-07-10 • Ahnlab

AhnLab’s June 2025 domestic APT monitoring found spear phishing remained the dominant intrusion method against South Korean targets, with LNK-based delivery accounting for the largest share and HWP-based attacks increasing from the previous month. One obs…

#LNK
2025-07-09 • Chainalysis

Greek authorities froze cryptocurrency linked to the February 2025 Bybit hack after tracing funds from a suspicious transaction back to wallets used in the roughly $1.5 billion theft, which the excerpt says is widely attributed to North Korea’s Lazarus Gr…

#Lazarus #Bybit
2025-07-04 • Wav3

Wav3 examines how defenders can detect obfuscated PiKVM and TinyPilot KVM-over-IP devices in endpoint telemetry, noting that North Korean state-sponsored actors have shown interest in similar remote-access hardware. The article focuses on CrowdStrike USB …

#ITWorker #PiKVM #TinyPilot