« 2026

387 reports

2026-04-07 • Sad Sec

A suspected Kimsuky phishing operation used a Korean Army K-ICTC themed lure to target military, defense, diplomacy, and related research audiences. The victim-facing archive contained a convincing invitation PDF and a PDF-disguised LNK shortcut that down…

#Kimsuky #AppleSeed
2026-04-07 • Walmart

Jason Reaves links NodeJS stealer and backdoor infrastructure to activity resembling DPRK developer-targeting campaigns that use fake interviews or attacker-supplied code repositories. The excerpt shows an npm package, npm-doc-builder, executing a postins…

#OtterCookie
2026-04-05 • Drift Protocol

Drift describes an April 2026 compromise that followed months of relationship-building by personas posing as a quantitative trading firm seeking protocol integration. The attackers allegedly engaged Drift contributors at conferences, created a Telegram gr…

#UNC4736 #DriftProtocol