« 2026

387 reports

2026-03-09 • Google

Google Cloud’s H1 2026 Threat Horizons report includes a DPRK-relevant case where North Korean actors used living-off-the-cloud techniques after social engineering created a personal-to-corporate access path. The actors bypassed traditional network perime…

#UNC4899 #UNC5267
2026-03-02 • RUSI

RUSI assesses the UK-Republic of Korea Strategic Cyber Partnership as a vehicle for improving joint cyber resilience, deterrence, information sharing, and technology cooperation. The paper recommends expanding government, academic, research, and commercia…

2026-03-02 • Moonlock

Moonlock Lab tracks a campaign targeting cryptocurrency and Web3 professionals through LinkedIn outreach, fabricated venture capital firms, and fake Zoom or Google Meet links. The attack flow uses recruiter or investor personas tied to fronts such as Soli…

#UNC1069 #ClickFix
2026-03-02 • Ctrl Alt Intel

Ctrl-Alt-Intel observed suspected DPRK-linked intrusions against cryptocurrency organizations, including staking platforms, exchange software providers, and exchange cloud tenants. The activity combined React2Shell scanning and exploitation with separate …

#React2Shell #T1090 #T1071.001 #T1046 #T1552.001 #T1552.004 #T1550.001 #T1190 #T1555.006 #T1213.006 #T1213.003 #T1651 #T1530 #T1526 #T1619 #T1021.007 #T1078.004 #T1059.009 #T1087.004 #T1580 #T1578.005
2026-03-01 • Knowyouradversary

Know Your Adversary describes APT37 activity tracked as Squid Werewolf using the RESTLEAF implant with abuse of Zoho WorkDrive, a legitimate cloud file-management and collaboration platform. The excerpt focuses on proactive hunting for communications to w…

#APT37