« 2025 »

778 reports

2025-06-26 • Bitso

Bitso’s Quetzal Team describes an attempted DPRK IT worker infiltration in which a suspicious applicant using a Mexican identity moved through engineering interviews before being rejected. The team links the activity to “Famous Chollima” style wage-mole o…

#FamousChollima
2025-06-25 • Christophe

The video description presents North Korean IT workers as using fake identities, polished resumes, professional headshots, and deceptive video-call setups to obtain remote technology jobs. It says thousands of workers have targeted companies in the United…

#Youtube #ITWorker
2025-06-25 • Socket

Socket attributes a continuing North Korean Contagious Interview supply-chain campaign to 35 malicious npm packages published across 24 accounts, including six packages that remained live and had more than 4,000 downloads. The packages target developers a…

#NPM #ContagiousInterview #BeaverTail #HexEval #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1056.001 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2025-06-23 • Darkatlas

Dark Atlas frames Bluenoroff, also known as APT38, as a financially motivated North Korean Lazarus subgroup linked to the Reconnaissance General Bureau and focused on banks, SWIFT endpoints, casinos, ATMs, and cryptocurrency platforms. The hunt starts fro…

#Bluenoroff