« 2026

387 reports

2026-02-26 • Zscaler

Zscaler ThreatLabz links the Ruby Jumper campaign to APT37, also tracked as ScarCruft, Ruby Sleet, and Velvet Chollima, and describes new tooling for surveillance and air-gapped environments. The infection begins with malicious LNK files that launch Power…

#APT37 #LNK #T1125 #T1082 #T1567.002 #T1113 #T1083 #T1056.001 #T1204.001 #T1027 #T1057 #T1053.005 #T1059.001 #T1036.005 #T1055 #T1620 #T1123 #T1052.001 #T1132.002 #T1574 #T1564.001 #T1092
2026-02-24 • Kudelski Security

Kudelski Security examines the DPRK fake IT-worker fraud ecosystem as a blended operation involving North Korean workers, recruited helpers, fake identities, and supporting cybercrime services. The excerpt says workers approach developers in countries inc…

#ITWorker
2026-02-22 • Kmsec

The post tracks FAMOUS CHOLLIMA operator infrastructure by using npm publish notification emails exposed through insecure temporary-mail providers. The author says DPRK-linked npm operators used disposable domains registered through services such as email…

#NPM #FamousChollima
2026-02-21 • Kmsec

FAMOUS CHOLLIMA used express-core-validator v1.0.1, published by npm user crisdev09 on 20 February 2026, to test Google Drive as a stager in its Contagious Interview npm activity. The package’s postinstall chain loaded core.js, retrieved a Google Drive fi…

#NPM #FamousChollima