« 2026

387 reports

2026-03-23 • Secure Works

NICKEL ALLEY is described as a North Korean government-linked threat group focused on espionage and surveillance. The group targets technology-sector professionals by advertising fake job opportunities and moving victims through a fraudulent interview pro…

#NickelAlley
2026-03-19 • Ahnlab

AhnLab observed February 2026 APT activity targeting South Korea, with spear phishing as the dominant delivery method and LNK files the most common attachment type. One LNK chain contacted an external URL through PowerShell, copied curl.exe under another …

#Phishing #LNK
2026-03-18 • Flare

Flare Research and IBM X-Force describe North Korean IT worker operations that use false personas, freelance platforms, and full-time remote roles to generate revenue for the DPRK state and sometimes enable espionage, theft, extortion, or cryptocurrency t…

#ITWorker
2026-03-18 • Bitrefill

Bitrefill says a March 1, 2026 intrusion showed similarities to past DPRK Lazarus/Bluenoroff attacks on cryptocurrency companies, citing modus operandi, malware, on-chain tracing, and reused IP and email addresses. Initial access came from a compromised e…

#Bluenoroff #Bitrefill
2026-03-17 • Break Glass Intelligence

Breakglass analyzed two samples from a Hungarian incident as evidence that Lazarus Group operated as a Medusa ransomware-as-a-service affiliate rather than only deploying DPRK-built ransomware. The TSMSISrv.dll loader is attributed to Lazarus-linked trade…

#Ransomware #Lazarus #Medusa #T1082 #T1555 #T1059.001 #T1036.005 #T1574.002 #T1562.001 #T1490 #T1486 #T1547.014 #T1129 #T1622 #T1135 #T1027.002 #T1546.015 #T1489