« 2026

387 reports

2026-06-16 • NISOS

Nisos identified a DPRK state-sponsored employment fraud cell that submitted more than 170,000 job applications to US companies between December 2024 and September 2025, producing 76 employment offers across 22 operatives. The operation used appropriated …

#ITWorker #PiKVM #T1585
2026-06-15 • Roman

A developer-targeted LinkedIn recruiting lure sent the author to a public GitHub repository containing a hidden Node.js backdoor. The malicious code in `app/test/index.js` assembled `https://rest-icon-handler.store/icons/77` and was designed to execute wh…

#Phishing #GitHub #NPM
2026-06-14 • Genians

APT37 used Microsoft-themed spear phishing to deliver a ZIP archive containing a malicious LNK file that launched a PowerShell and batch-based infection chain. The chain installed an official embedded Python runtime, executed compiled Python bytecode disg…

#APT37 #LNK #T1059.003 #T1567.002 #T1113 #T1071.001 #T1497 #T1056.001 #T1027 #T1204.002 #T1566.001 #T1053.005 #T1059.001 #T1102 #T1497.001 #T1105 #T1123 #T1025 #NarwhalRAT
2026-06-14 • Genians

APT37-linked operators used Microsoft account security-themed spear phishing against Korean users to deliver NarwhalRAT through a ZIP-contained malicious LNK, obfuscated BAT scripts, copied curl execution, and a Python embedded runtime. The malware chain …

#APT37 #LNK #T1059.003 #T1567.002 #T1113 #T1071.001 #T1497 #T1056.001 #T1027 #T1204.002 #T1566.001 #T1053.005 #T1059.001 #T1102 #T1497.001 #T1105 #T1123 #T1025 #NarwhalRAT
2026-06-11 • Humanity

A phishing email impersonating Bithumb led Humanity Protocol director Chong Yee Wai to download a malicious attachment from an attacker-controlled host, after which a Hancom-signed loader and remote-access tooling gave the attacker control of his Windows …

#Phishing #HumanityProto
2026-06-10 • Kmsec

Google Docs lures tied to FAMOUS CHOLLIMA show how the DPRK-nexus actor advertises fake jobs, targets developers with malicious interview tasks, and recruits proxy interview facilitators. The research pivots on Google Docs titles, resource hashes, outgoin…

#FamousChollima