« 2025 »

778 reports

2025-11-09 • Wickeren

The research tracks UNC3782 infrastructure first pivoted from Mandiant-shared indicators and finds extensive phishing activity impersonating Naver Corp from 2021 through late 2022. The author identifies hundreds of Naver typosquat domains, WHOIS registrat…

#Phishing #UNC3782
2025-11-08 • Bitso

Bitso's Quetzal Team describes another attempted DPRK-aligned remote hiring infiltration involving a Colombian software engineer persona named Sebastian who failed live interview scrutiny. The excerpt says the persona claimed native Spanish ability, delet…

#FamousChollima
2025-11-07 • ENKI

ENKI analyzes a Lazarus Group Comebacker variant recovered from office-theme[.]com, where malicious DOCX files with VBA macros acted as droppers for a staged loader chain. The lures impersonated aerospace and defense-related organizations including Edge G…

#Comebacker #Lazarus #T1027.013 #T1059.003 #T1140 #T1071.001 #T1204.002 #T1059.005 #T1566.001 #T1547.001 #T1583.001 #T1059.001 #T1132.001 #T1102 #T1204.005 #T1620 #T1573.001 #T1218.011 #T1027.015 #T1547.000
2025-11-06 • Logpresso

Logpresso assesses that a late-October 2025 attack using a health-check notice lure was conducted by the North Korea-linked Kimsuky group. The intrusion relied on an archive containing a JSE file disguised as a PDF, which displayed a benign document while…

#Kimsuky
2025-11-05 • Sophos

Sophos publishes a defensive playbook for organizations facing North Korean IT-worker impersonation, a scheme it says has expanded from U.S. technology companies into finance, healthcare, government, and other regions. The guidance is based on Sophos’s in…

#ITWorker