« 2025 »

778 reports

2025-03-19 • Threat Book

Trend, Kimsuky, Konni is described as a cyber threat report requiring defender review of the published evidence. The source discusses attacker tradecraft, victim targeting, malware or infrastructure references, and operational context that may affect dete…

#Trend #Kimsuky #Konni #Lazarus
2025-03-19 • Trmlabs

TRM Labs reports that North Korea-linked cryptocurrency hacks continued in 2024, with nearly USD 800 million stolen. The excerpt places that activity in a broader illicit-crypto landscape where overall illicit volume declined by 24%, while ransomware paym…

#Trend #Cryptocurrency
2025-03-18 • KRCERT

KISA warns that vulnerable INNORIX Agent versions 9.2.18.001 through 9.2.18.538 can allow external file download and execution, creating an exploitation path that could be abused for malware delivery or follow-on compromise. Affected organizations are adv…

#Innorix
2025-03-18 • NKInternet

Connectivity to North Korea-linked AS131279 dropped on March 18, 2025 after changes to the SOA record and Route Origin Authorization for 175.45.176.0/22. The new ROA authorized AS131279 as the origin but set the maximum prefix length to /22, while the net…

#Trend
2025-03-17 • OKX

OKX says it detected a coordinated Lazarus effort to misuse its DeFi services through OKX Web3, which it characterizes as a DEX aggregator rather than a custodian of customer assets. In response, the company temporarily suspended its DEX aggregator servic…

#News #Bybit
2025-03-17 • Sygnia

Sygnia summarizes the February 2025 Bybit heist as a multi-stage compromise attributed by the FBI to TradeTraitor, also known as Lazarus Group and UNC4899. The attack began with a Safe{Wallet} developer's macOS workstation, likely compromised through soci…

#Bybit #SafeWallet
2025-03-15 • Slowmist

SlowMist analyzes a LinkedIn recruiting lure that pushed a blockchain engineer toward a Bitbucket project for a supposed Socifi game and staking platform. The repository hid a malicious payload far to the right of an otherwise normal-looking server.js lin…

#ContagiousInterview