« 2025 »

778 reports

2025-11-20 • Jfrog

JFrog found a two-part npm cryptocurrency stealer that paired a benign-looking Ethereum address validation package with a malicious transitive dependency. The visible package exported ordinary address-checking functions, but dynamically imported aes-core-…

#NPM
2025-11-20 • Bloo

The excerpt attributes EPOINT-AES to North Korean state-sponsored activity and describes a multi-stage Windows malware framework recovered from compromised systems. Its attack chain starts with a DLL executed through rundll32, decrypts AES-protected shell…

2025-11-19 • Chainalysis

North Korean IT workers are described as a covert extension of state-sponsored cyber operations, posing as freelance developers and contractors inside legitimate companies. The excerpt says they are often paid in cryptocurrency and generate revenue for No…

#ITWorker
2025-11-18 • BSides Pyongyang

BSides Pyongyang 2025 features multiple talks centered on DPRK cyber activity, including cryptocurrency theft, laundering, IT worker schemes, counterintelligence, and malware analysis. The excerpt describes North Korea as a prolific cryptocurrency threat …

#Youtube
2025-11-18 • Chollima Group

Chollima Group uses the MSMT sanctions report to reframe its prior research on DPRK IT worker networks, especially activity tied to Tanzania, Guinea, Nigeria, and other African locations. The article links the Tanzania-based Bells Inter Trading cluster an…

#ITWorker #MoonstoneSleet