« 2026

387 reports

2026-01-20 • Piolink

Kimsuky is described using malicious QR codes in spearphishing emails to move victims from managed desktops to less-protected mobile devices and evade URL inspection and sandboxing. The campaign targets think tanks, academic institutions, government-relat…

#Kimsuky #DocSwap
2026-01-20 • Picus Security

BlueNoroff is presented as the financially motivated arm of Lazarus, evolving from SWIFT and bank intrusions such as the Bangladesh Central Bank heist into sustained cryptocurrency and Web3 targeting. The excerpt traces campaigns including SnatchCrypto, f…

#Bluenoroff #T1082 #T1005 #T1587.001 #T1071.001 #T1059.007 #T1566.002 #T1566.003 #T1543.001 #T1059.005 #T1583.003 #T1204.004 #T1547.001 #T1583.001 #T1036.005 #T1552.001 #T1059.002 #T1055 #T1562.001 #T1027.002 #T1593 #T1589 #T1016 #T1018 #T1548.002 #T1598.001 #T1074.001 #T1087.001 #T1588.002 #T1056.002 #T1176.001 #T1543.004 #T1027.010 #T1548.006 #T1657
2026-01-19 • Ahnlab

North Korean state-sponsored groups are described as expanding hybrid intrusion models that combine fake IT employment schemes, remote-work abuse, and malware delivery changes. Famous Chollima targeted U.S. and Western companies through fraudulent remote …

#Trend #Lazarus #FamousChollima
2026-01-14 • Ahnlab

AhnLab’s December 2025 South Korea APT telemetry found spear phishing as the dominant delivery method, with LNK-based attacks accounting for the largest share of observed activity. The LNK chains executed malicious PowerShell commands to download payloads…

#Trend #LNK