« 2025 »

778 reports

2025-04-16 • Ketman

Ketman links multiple suspicious GitHub and Web3 freelance personas to DPRK IT worker activity on open source and pay-for-PR platforms, with onlyDust payments observed for accounts including 0xExp-po, bestselection18, and aidenwong812/cryptogru812. The in…

#ITWorker
2025-04-15 • Plainbit

The source discusses cooperation patterns among state-backed intrusion groups and focuses on North Korean operators' use of Windows LNK shortcut malware for initial access. It highlights how LNK file structure, embedded environment artifacts, and repeated…

#Kimsuky #Konni #LNK #Slides
2025-04-14 • Wired

The FBI attributed the nearly $1.5 billion Bybit cryptocurrency theft to TraderTraitor, a North Korean hacking group also tracked as Jade Sleet, Slow Pisces, and UNC4899. The group is described as a Lazarus-linked, cryptocurrency-focused actor that target…

#News #TraderTraitor