« 2025 »

778 reports

2025-05-27 • Hauri

Hauri analyzed a tax-notice-themed LNK attack that launches mshta.exe to retrieve txjyh.hta from cdn.glitch.global and execute an information-stealing chain. The HTA displays a tax.pdf decoy and branches on Windows Defender status: Defender-enabled hosts …

#LNK
2025-05-27 • Recorded Future

The excerpt is a Click Here podcast feed entry for a May 27, 2025 episode titled “227 new reasons to worry about North Korea,” but it does not include a transcript or technical episode body. The feed context shows the program covers cyber and intelligence…

#Podcast
2025-05-23 • S3N4T0R

The simulation models a Velvet Chollima attack chain attributed in the excerpt to a January 2025 campaign against South Korean government officials, NGOs, government agencies, and media organizations across multiple regions. The described delivery starts …

#VelvetChollima
2025-05-19 • NISOS

Nisos tracks the Saja DPRK Employment Scam Network as a likely DPRK-affiliated IT worker operation seeking remote engineering and full-stack blockchain roles. The actors posed as Polish and U.S. nationals through GitHub accounts, portfolio sites, freelanc…

#ITWorker