« 2025 »

778 reports

2025-01-23 • USFBI

The FBI warned that North Korean IT workers have expanded beyond revenue generation into data theft and extortion against U.S. businesses. Recent cases include workers using unlawful network access to exfiltrate proprietary data and code, copy repositorie…

#ITWorker
2025-01-23 • NISOS

Nisos traced a likely DPRK IT worker who appears to have used multiple personas to obtain remote software engineering and full stack developer roles with Japanese companies. The investigation pivoted from an email address cited in a UN sanctions report to…

#ITWorker
2025-01-21 • lazarusholic

Trend, Youtube is described as a cyber threat report requiring defender review of the published evidence. The source discusses attacker tradecraft, victim targeting, malware or infrastructure references, and operational context that may affect detection e…

#Trend #Youtube
2025-01-21 • USCOURTS

A U.S. civil forfeiture complaint seeks approximately 942,462.845 USDT in connection with an investigation into identity theft, computer fraud, wire fraud, money laundering, and related conspiracies. The excerpt establishes the legal basis for seizing vir…

#ITWorker #Solareum
2025-01-21 • NSHC

NSHC's JSAC presentation describes a June 2024 Kimsuky social-engineering operation that used LinkedIn reconnaissance against Republic of Korea Navy-related personnel and then moved into spear phishing. The actors prepared VPS/VDS infrastructure, used mai…

#Kimsuky #Slides
2025-01-21 • lazarusholic

The JSAC source presents Lazarus-focused CTI methods for following clues across malware, infrastructure, and external knowledge bases such as Malpedia and the Pyramid of Pain. The report is useful as analytic tradecraft for strengthening Lazarus attributi…

#Trend #Slides