« 2025 »

778 reports

2025-04-10 • Zoth

Zoth's April 2025 incident report says attackers used social engineering against a service provider to gain access to the Zoth deployer wallet and perform an unauthorized contract upgrade against the ZeUSD platform. The malicious upgrade used upgradeToAnd…

#Zoth
2025-04-09 • Thanh

A developer analyzed a crypto job scam in which an impersonated recruiter pushed a technical assessment that required downloading and running a code repository. Review of the dependencies found a suspicious Go package, github.com/TedCollin/uniroute/v2, co…

#Scam
2025-04-09 • Veracode

Veracode describes a renewed North Korean npm malware campaign that targets developers with malicious packages disguised as logging, validation, React, or utility libraries. The packages appear designed for social-engineering workflows in which a target r…

#NPM #Lazarus
2025-04-04 • Ketman

Ketman follows up on Nisos reporting about North Korean IT worker GitHub accounts and identifies additional connected personas with unusual Russian military imagery. Two linked accounts used Kinzhal hypersonic-missile related avatars traced to Russian for…

#ITWorker
2025-04-04 • Rekt

Rekt News describes the alleged exposure of the Nick Franklin persona as part of a North Korea-linked social-engineering network targeting Web3 security researchers and protocols. The article says Anton Bukev's warning about a malicious macOS app led inve…

#Cryptocurrency #RadiantCapital #Scam
2025-04-03 • Rewterz

Rewterz summarizes active indicators tied to the North Korea-linked Konni APT, a cyber-espionage group active since at least 2014. The source describes Konni RAT delivery through phishing messages or emails, with weaponized files leading to implants that …

#Konni