« 2026

387 reports

2026-04-20 • Kelp DAO

Kelp says rsETH was drained on April 18 through a forged cross-chain message after two LayerZero-hosted RPC nodes were compromised and a third RPC node was hit by a simultaneous DDoS attack. The statement frames the incident as an attack on LayerZero infr…

#KelpDAO
2026-04-20 • Nox Hunt

NoxHunt uses infostealer telemetry and ZachXBT’s prior findings to examine compromised systems tied to suspected DPRK overseas IT worker operations. The activity centers on fraudulent remote development work supported by VPN obfuscation, fake identities a…

#ITWorker
2026-04-20 • Layer Zero

KelpDAO’s April 18, 2026 exploit involved about $290 million in losses and is described as likely attributable to DPRK’s Lazarus Group, specifically TraderTraitor. The incident was isolated to KelpDAO’s rsETH configuration because it used a 1-of-1 LayerZe…

#TraderTraitor #KelpDAO
2026-04-17 • Break Glass Intelligence

Breakglass Intelligence maps a large Kimsuky credential-harvesting operation targeting South Korean users through Naver, National Tax Service, NHIS, NongHyup, National Pension Service, and Kakao impersonation themes. The investigation consolidates six inf…

#Kimsuky #Phishing #T1102.002 #T1082 #T1140 #T1041 #T1113 #T1608.001 #T1071.001 #T1115 #T1083 #T1497 #T1056.001 #T1204.001 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1567 #T1057 #T1059.005 #T1583.006 #T1583.003 #T1204.004 #T1518.001 #T1568.001 #T1566.001 #T1547.001 #T1585.002 #T1056.003 #T1053.005 #T1539 #T1608.005 #T1598.003 #T1590.005 #T1583.001 #T1059.001 #T1036.005
2026-04-17 • meowmfer

A thread links the fake identity "Taro Aikuchi" to a DPRK IT worker cluster labeled "215" through repeated numeric markers across GitHub handles, email addresses, commit metadata, and aliases. The excerpt connects 0xbomb215, xsen215, highgoal215, and rela…

#ITWorker