« 2025 »

778 reports

2025-03-10 • NCCGroup

To perform this attack, the attackers targeted Safe{Wallet}, a widely used multi-signature wallet solution that required multiple approvals (in Bybit’s case, at least three signers) before executing a transaction. These changes were subtle and specificall…

#Bybit #SafeWallet
2025-03-10 • Socket

North Korea’s Lazarus Group continues to infiltrate the npm ecosystem, deploying six new malicious packages designed to compromise developer environments, steal credentials, extract cryptocurrency data, and deploy a backdoor. The secondary payload (SHA256…

#NPM #Lazarus #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2025-03-10 • ZW01f

By 2023, APT37 had shifted to phishing campaigns targeting users on both Windows and Android platforms. Infection Vector: The attack begins with phishing emails containing ZIP attachments that hide malicious LNK files, masquerading as documents related to…

#APT37 #RokRAT #LNK
2025-03-07 • Arkm

Arkham reports that Lazarus laundered the Bybit ETH cold-wallet proceeds by bridging 500,000 ETH, worth about $1.3 billion, from Ethereum into native Bitcoin. About 72% moved through THORChain, with other flows using THORChain frontends, AsgarDEX, and eXc…

#Lazarus #Bybit
2025-03-07 • Mandiant

GTIG says North Korean IT workers have expanded beyond salary fraud into extortion, data theft, and operations inside corporate virtual desktops, networks, and servers. The scheme uses fake identities, resumes, profiles, and remote technical roles to plac…

#ITWorker