« 2026

387 reports

2026-01-14 • OZ

The write-up documents a developer recruitment scam presented as DPRK-linked activity under DEV#POPPER, Contagious Interview, and the XCTDH technique. A Discord persona posing as a hiring lead for a React developer role approached targets in developer and…

#ContagiousInterview #DevPopper
2026-01-13 • Cyfirma

CYFIRMA profiles Kimsuki as a North Korea-linked APT active since at least 2012 and aligned with strategic intelligence collection priorities associated with the Reconnaissance General Bureau. The group is described as targeting South Korean and U.S.-base…

#Kimsuky #T1102.002 #T1059.003 #T1567.002 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1059.005 #T1583.006 #T1566.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1566 #T1585.001 #T1656 #T1205 #T1105 #T1055 #T1553.002 #T1620 #T1102.001 #T1027.002 #T1133 #T1190 #T1593 #T1588.002 #T1657 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1585 #T1593.002 #T1598 #T1583 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1588.003 #T1589.003 #T1594 #T1218.010 #T1557 #T1219.002 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1596
2026-01-13 • Ahnlab

AhnLab's December 2025 domestic APT trend report says spear phishing dominated observed attacks against South Korean targets, with LNK files accounting for the largest share that month. One LNK-based pattern executed malicious PowerShell from compressed a…

#Trend #LNK
2026-01-12 • Red Asgard

Red Asgard maps active Lazarus Group infrastructure discovered while vetting a cryptocurrency Upwork project containing Contagious Interview-style malware. The repository used VS Code auto-execution, a malicious npm dependency, and backend Function.constr…

#ContagiousInterview #Lazarus #T1555 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1547.001 #T1053.005 #T1539 #T1036.005 #T1102.001 #T1562.001 #T1027.002 #T1573.001 #T1496 #T1573.002 #T1048.003
2026-01-12 • Silentpush

Silent Push describes the DPRK remote worker program as an insider-risk and revenue-generation operation that uses stolen identities, remote hiring, and deceptive network paths to enter Western companies. The report separates long-term infiltrators, who m…

#ITWorker
2026-01-05 • deeveeaar

The excerpt alleges North Korean government and military involvement in scams targeting Americans, but it provides only a YouTube description and timestamps rather than a technical intrusion report. It says anonymous sources provided evidence and material…

#Youtube #ITWorker
2026-01-01 • Objective-see

Objective-See’s 2025 macOS malware review shows information stealers as the dominant new macOS malware class, with victims’ cookies, passwords, certificates, cryptocurrency wallets, SSH keys, and related sensitive data as primary collection targets. The e…

#macOS #Koi #RustDoor #RNStealer