« 2026

387 reports

2026-05-29 • Poly Swarm

Lazarus-linked operators are using a three-stage malware framework, DPAPILoader, RemotePELoader, and RemotePE, to maintain stealthy long-term access in financial and cryptocurrency environments. DPAPILoader decrypts victim-bound payloads with Windows DPAP…

#Cryptocurrency #AppleJeus #Fileless #Finance #UNC4736 #FinancialGain #Espionage #CitrineSleet #Lazarus #GleamingPisces #POOLRAT #PondRAT #RemotePE #ThemeForestRAT #T1071.001 #T1027 #T1055 #T1562.006
2026-05-28 • Safe Dep

A malicious npm package, js-logger-pack, evolved from a probe into a dropper for MicrosoftSystem64, a cross-platform Node.js Single Executable Application that functions as an infostealer and RAT. The payload targets browser credentials, more than 80 cryp…

#NPM #FamousChollima #T1102.002 #T1119 #T1059.003 #T1567.002 #T1005 #T1113 #T1195.002 #T1056.001 #T1567 #T1543.001 #T1552 #T1547.001 #T1053.005 #T1059.001 #T1053 #T1102 #T1059 #T1195 #T1543 #T1552.004 #T1543.004 #T1547 #T1056 #HuggingFace
2026-05-27 • Wiz

Wiz identified JINX-0164, a previously unreported financially motivated actor targeting cryptocurrency organizations and developers through LinkedIn recruitment/business lures, fake conferencing pages, and malicious macOS “fix” scripts. The actor deploys …

#Suspicious #macOS #T1480.001 #T1555 #T1195.002 #T1056.001 #T1059.004 #T1552 #T1566 #T1059 #T1105 #T1547 #JINX-0164
2026-05-27 • ENKI

ENKI Whitehat identified Kimsuky malware delivery activity through April 2026 against South Korean military and enterprise-related targets. The campaigns used tailored lures, including fake domestic security software installation pages and a fake Webex me…

#Kimsuky #T1636.004 #T1027.013 #T1140 #T1041 #T1113 #T1071.001 #T1059.007 #T1204.002 #T1547.001 #T1053.005 #T1132.001 #T1566 #T1497.001 #T1620 #T1573.001 #T1027.010 #T1027.009 #T1055.001 #HttpSpy #JSONPing
2026-05-27 • ENKI

ENKI Whitehat reported Kimsuky malware delivery cases targeting South Korean military and corporate environments through April 2026. The actor used fake security software installation pages and a Webex-themed lure based on a legitimate meeting schedule, w…

#Kimsuky #T1636.004 #T1027.013 #T1059.003 #T1090 #T1140 #T1070.004 #T1071.001 #T1059.007 #T1027 #T1204.002 #T1547.001 #T1053.005 #T1132.001 #T1566 #T1497.001 #T1620 #T1573.001 #T1070.006 #T1055.001 #HttpSpy #JSONPing
2026-05-26 • Ahnlab

AhnLab observed April 2026 APT activity against South Korean targets, with most infections beginning through spear-phishing emails that used spoofed senders, malicious attachments, and malicious links. The activity relied heavily on LNK files, PowerShell,…

#Phishing #LNK