« 2025 »

778 reports

2025-06-23 • Poly Swarm

Famous Chollima, described as a North Korean-aligned actor, deployed the Python-based PylangGhost RAT against cryptocurrency and blockchain professionals, primarily in India. The campaign used fake recruiter personas and counterfeit job-application sites …

#FamousChollima #PylangGhost
2025-06-20 • Field Effect

Field Effect investigated a compromise at a Canadian online gambling provider that it says may be associated with BlueNoroff, a financially motivated North Korean Lazarus subgroup. The victim joined a cryptocurrency-related Zoom meeting with an impersonat…

#Bluenoroff
2025-06-19 • evstykas

The archived thread describes exposed backend code and credentials for a malware delivery operation attributed in the text to generic North Korean threat actors, explicitly not Lazarus. The backend emailed operators when victims interacted with the malwar…

2025-06-19 • Bito Pro

BitoPro says forensic findings from its May 9, 2025 cryptocurrency theft showed no internal personnel involvement and that the tradecraft resembled incidents attributed to North Korea’s Lazarus Group. The attackers socially engineered a cloud operations e…

#Lazarus #BitoPro
2025-06-18 • Ketman

Ketman identifies a suspected DPRK IT worker-related GitHub account, AhegaoXXX, with privileged control over the Keeper-Wallet organization tied to Waves Protocol. After nearly two years of inactivity, the account pushed dependency updates, could create r…

#NPM #ITWorker