« 2026

387 reports

2026-02-11 • Okta

Okta Threat Intelligence examines DPRK IT-worker fraud through two tracked personas drawn from a larger dataset of more than 130 actors and 6,500 interviews across 500 companies. The examples show actors using free webmail accounts, job and coding platfor…

#ITWorker
2026-02-06 • S2W

ScarCruft is reported shifting recent ROKRAT delivery from its earlier LNK-based chain to Hangul HWP documents carrying OLE-embedded droppers, loaders, or downloaders. The cases described use DLL side-loading, hardcoded payload retrieval, steganographic s…

#Scarcruft #RokRAT
2026-02-04 • Rekt

Step Finance lost roughly 261,854 to 261,932 SOL after compromised executive devices enabled an attacker to transfer stake authorization and withdraw treasury funds. The article frames the incident as likely social engineering or phishing-driven key compr…

#StepFinance
2026-02-03 • Shubho57

The analyzed Kimsuky-linked JSE file acts as a multi-stage Windows script dropper that embeds a twice-base64-decoded PE executable and writes it to disk for execution. The script abuses Windows Script Host components including FileSystemObject, ADODB Stre…

#Kimsuky #JSE
2026-02-03 • Red Asgard

Red Asgard's follow-up investigation into the Contagious Interview campaign found that the suspected C2 infrastructure was operational rather than a honeypot, exposing 241,764 stolen credentials from 857 victims across 90 countries. The victim set centere…

#ContagiousInterview #Lazarus #T1005 #T1113 #T1560 #T1071.001 #T1056.001 #T1204.002 #T1566.003 #T1555.003 #T1547.001 #T1053.005 #T1552.001 #T1497.001 #T1219 #T1102.001 #T1027.002 #T1573.001 #T1530 #T1114 #T1098 #T1496 #T1087 #T1573.002
2026-02-01 • Red Asgard

Red Asgard’s Contagious Interview follow-up identifies OtterCookie as a second malware family operating alongside BeaverTail/InvisibleFerret in the same campaign infrastructure. The payload from tetrismic.vercel.app used C2 172.86.105.40:5918 and supporte…

#Lazarus #OtterCookie #T1113 #T1020 #T1115 #T1497 #T1056.001 #T1059.007 #T1027 #T1204.002 #T1566.003 #T1555.003 #T1547.001 #T1053.005 #T1497.001 #T1102.001 #T1027.002 #T1573.001 #T1496 #T1573.002 #T1528