« 2025 »

778 reports

2025-11-03 • Crowd Strike

CrowdStrike’s European threat landscape report says DPRK-nexus adversaries conducted operations targeting Ukrainian entities during the period dominated by Russia’s invasion-related cyber activity. The DPRK section appears within a broader nation-state ov…

#Trend #Chollima
2025-11-03 • Bitso

Quetzal reports another suspected Famous Chollima hiring attempt after earlier failed interviews, this time involving a candidate using the name Julian Arleby Munoz Mendez for a company role. The applicant allegedly copied a Colombian senior full-stack en…

#FamousChollima
2025-10-30 • Bitso

Bitso's Quetzal Team describes two suspected Famous Chollima job-infiltration attempts against a Senior Software Engineer opening at a financial and crypto company. The candidates used stolen resumes, fabricated Mexican identities, LinkedIn profiles, AI-a…

#FamousChollima
2025-10-30 • KDI

North Korea is described as expanding cyber operations into a major revenue and strategic tool as sanctions restrict traditional foreign-currency channels. The excerpt cites Chainalysis data that North Korean cryptocurrency theft reached about $1.34 billi…

#Whitepaper
2025-10-27 • Ransom ISAC

Ransom-ISAC analyzed a suspected DPRK-affiliated campaign that used a weaponized private GitHub repository to compromise cryptocurrency and developer environments. The attack chain combined DEV#POPPER.js, a cross-platform JavaScript payload, with OmniStea…

#DevPopper #EtherHiding #T1082 #T1140 #T1005 #T1041 #T1071.001 #T1059.006 #T1059.007 #T1027 #T1204.002 #T1555.003 #T1567 #T1566 #T1195 #T1219 #T1547 #T1573 #T1095