« 2025 »

778 reports

2025-10-18 • Picus Security

Picus profiles Lazarus Group, also known as APT38 or Hidden Cobra, as a North Korea-linked threat group active since at least 2009 across espionage, sabotage, and financial theft operations. The overview ties the group to major activity including the Sony…

#Lazarus #T1027.013 #T1567.002 #T1041 #T1204.002 #T1547.001 #T1566 #T1486 #T1027.002 #T1189 #T1048.003 #T1134.002 #T1027.007 #T1068 #T1021.001 #T1574.001 #T1095 #T1047 #T1574.013 #T1561.001 #T1027.009 #T1074
2025-10-17 • Microsoft

Microsoft frames the 2025 cyber defense landscape as a period of accelerating speed, scale, and sophistication driven by digital transformation and AI. The excerpt highlights hybrid ransomware and phishing, cybercrime-as-a-service, and the expanding role …

#Trend
2025-10-15 • Huntress

The provided markdown excerpt for Bluenoroff's Clues does not contain readable CTI analysis beyond the title and source URL. The body appears to be binary export data beginning with a ZIP-style PK header and embedded media/file content rather than extract…

#Bluenoroff #Slides
2025-10-10 • Socket

Socket tracks North Korea’s Contagious Interview operation as a weekly, wave-based abuse of npm, identifying more than 338 malicious packages with over 50,000 downloads and 25 still live at publication time. The campaign uses fake recruiter personas, Link…

#NPM #ContagiousInterview #T1027.013 #T1082 #T1119 #T1005 #T1041 #T1608.001 #T1195.002 #T1083 #T1059.007 #T1204.002 #T1555.003 #T1105 #T1657 #T1555.001 #T1546.016 #T1217
2025-10-09 • KELA

KELA links a large North Korean remote-worker operation to fake identities used to obtain freelance and full-time roles across technology, cryptocurrency, transportation, critical infrastructure, architecture, and industrial design. The workers rely on st…

#ITWorker
2025-10-07 • 38North

38 North examines how DPRK IT workers obtain remote jobs under fabricated or stolen identities to generate revenue and create insider-risk exposure for global employers. The report describes facilitators who supply false documents, procure laptops, run la…

#News #ITWorker