« 2025 »

778 reports

2025-04-01 • Google

Google Threat Intelligence Group reports that DPRK IT-worker operations have expanded beyond the United States into Europe while adopting more aggressive extortion and virtualized infrastructure tactics. One late-2024 worker operated at least 12 personas …

#Trend #ITWorker
2025-04-01 • ENKI

ENKI analyzed malware signed with a leaked Somansa code-signing certificate and assessed links to a North Korean APT cluster. The backdoor sample used command-and-control infrastructure under p-e[.]kr, a domain pattern the report says is frequently used b…

#Somansa #T1082 #T1059.003 #T1140 #T1070.004 #T1041 #T1113 #T1046 #T1083 #T1057 #T1590.005 #T1553.002 #T1573.001 #T1592 #T1132.002 #T1070.006 #T1134.002 #T1027.007 #T1106 #T1134.001 #T1033 #T1485 #T1565.001 #T1069.001 #T1030 #T1027.008
2025-03-27 • Priya Patel

A suspected Konni APT spear-phishing campaign used a malicious LNK file that launches mshta and extracts an embedded PowerShell script into C:\ProgramData. The script connects to 64.20.59.148 on ports 8855 and 6699, downloads a ZIP from Dropbox, and drops…

#Konni
2025-03-27 • NISOS

Nisos tracks likely DPRK-affiliated IT workers posing as Singaporean, Turkish, Finnish, and US nationals to obtain remote engineering and blockchain jobs. The report identifies reusable persona infrastructure, including GitHub portfolios, resumes, contact…

#ITWorker