Tag: korea
-
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-amazon-npm-attacks-sapphire-sleet/
-
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open”‘source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin. ClamAV is a widely used open”‘source antivirus engine maintained by the Cisco Talos team,…
-
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/koreas-largest-telco-kt-fine-39m/
-
North Korea’s APT Capabilities Are No Longer State-Exclusive
Tags: access, apt, cyber, finance, group, hacker, infrastructure, korea, lazarus, malware, military, north-korea, ransomware, skillsAhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns. Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military hackers allegedly used state-trained skills to steal bank funds, exposing cyber capability diffusion and blowback inside the regime. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-koreas-apt-capabilities-are-no-longer-state-exclusive-a-32392
-
South Korea Warns of State-Backed Watering Hole Attacks
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean…
-
Amazon pins multiple open source compromises on North Korea
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 incident affecting the axios NPM library First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646561/Amazon-pins-multiple-open-source-compromises-on-North-Korea
-
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aws-north-korea-axios-npm-supply/
-
South Korea fines telco giant KT $39 million for customer data breach
South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-39-million-for-customer-data-breach/
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software…
-
SourTrade Browser-Assembled Malware Defeats Hash-Based Detection by Design
SourTrade turns the browser itself into a malware build system, deliberately sidestepping the industry’s reliance on hash-based file fingerprints and traditional network-centric detection. SourTrade has been active since late 2024, abusing programmatic ads to reach retail traders and crypto investors in 12 geographies across APAC, LATAM, Africa, and Western markets, including Japan, Thailand, South Korea,…
-
Months-long breach exposes South Korean diplomats’ personal data
South Korea’s Foreign Ministry has disclosed that attackers breached the Korea National Diplomatic Academy’s online education system, compromising personal data … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/07/23/south-korea-diplomatic-academy-data-breach/
-
Hackers Lurked for 10 Months Inside South Korea Diplomatic System
The National Diplomatic Academy data breach has raised significant cybersecurity concerns in South Korea after the Ministry of Foreign Affairs confirmed that hackers maintained access to the academy’s online education system for nearly 10 months. The cyberattack resulted in the exposure of personal information belonging to current and former ministry employees, including diplomats serving overseas. First seen on thecyberexpress.com…
-
Unknown Attackers Remain Inside South Korean Diplomatic System for Nearly 10 Months
Unknown attackers maintained long-term, covert access to South Korea’s diplomatic training infrastructure for nearly ten months, exposing personal data tied to almost the entire diplomatic cadre and highlighting structural weaknesses in the Foreign Ministry’s security governance. South Korea’s Ministry of Foreign Affairs (MoFA) has confirmed a prolonged compromise of the Korea National Diplomatic Academy (KNDA)…
-
North Korean IT Worker Scams Fueling Ukrainian Invasion
Leaked Payment Server Data Lets Researchers Trace Money Flows. Salaries paid to North Korean IT workers end up converted to ammunition used against Ukraine, warns new research based on a trove of leaked payment server data. North Korea has for years smuggled remote and contract IT workers onto Western payrolls. First seen on govinfosecurity.com Jump…
-
South Korea discloses data breach impacting diplomats worldwide
South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), including overseas diplomats. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korea-discloses-data-breach-impacting-diplomats-worldwide/
-
North Korean Hackers Use Fake Job Interviews to Deploy PylangGhost and GolangGhost RATs
North Korea’s Famous Chollima threat group, also tracked as Wagemole, is actively running a sophisticated cyberespionage campaign dubbed ClickFake Interview. The operation targets cryptocurrency and Web3 professionals, tricking candidates into executing terminal commands that infect their devices with platform-specific Remote Access Trojans (RATs): PylangGhost on Windows and GolangGhost on macOS. Detailed analysis by the SOCRadar…
-
North Korea’s IT worker scheme funds Russia’s war effort, report finds
First seen on scworld.com Jump to article: www.scworld.com/brief/north-koreas-it-worker-scheme-funds-russias-war-effort-report-finds
-
South Korea proposes new rules for seizing self-custody crypto wallets
First seen on scworld.com Jump to article: www.scworld.com/brief/south-korea-proposes-new-rules-for-seizing-self-custody-crypto-wallets
-
North Korea’s IT worker scheme funds Russia’s war effort
DTEX researchers found a series of transactions in a payment wallet showing North Korean IT worker salaries flowing into sanctioned entities that support the regime’s military programs. First seen on cyberscoop.com Jump to article: cyberscoop.com/north-korea-it-worker-scheme-funds-russia-war-ukraine/
-
Hackers were inside South Korea’s diplomat training system for 9 months
Unidentified hackers compromised an online education system used by South Korea’s diplomatic academy, stealing personal information belonging to former and current employees of the country’s Ministry of Foreign Affairs. First seen on therecord.media Jump to article: therecord.media/south-korea-cyberattack-foreign-ministry
-
South Korea Military Faces Highest Cyberattack Volume Since 2021
Cyberattacks on South Korea military reached their highest level in five years in 2025, highlighting growing cybersecurity risks as the Ministry of National Defense struggles to retain trained cyber specialists. The rise in attacks, coupled with phishing emails and concerns over North Korea’s expanding cyber capabilities, has intensified calls for stronger defense measures. First seen on thecyberexpress.com Jump to…
-
South Korea Military Faces Highest Cyberattack Volume Since 2021
Cyberattacks on South Korea military reached their highest level in five years in 2025, highlighting growing cybersecurity risks as the Ministry of National Defense struggles to retain trained cyber specialists. The rise in attacks, coupled with phishing emails and concerns over North Korea’s expanding cyber capabilities, has intensified calls for stronger defense measures. First seen on thecyberexpress.com Jump to…
-
North Korea-Linked npm Packages Mimic Rollup Polyfills to Steal Developer Secrets
Threat actors with ties to North Korea have been linked to a fresh set of malicious npm packages that masquerade as Rollup polyfill tooling to facilitate remote access and data theft.According to JFrog, the packages “rollup-packages-polyfill-core” and “rollup-runtime-polyfill-core” mimic the legitimate “rollup-plugin-polyfill-node” project, down to the description, repository metadata, and First seen on thehackernews.com Jump…
-
Cryptohack Roundup: Chinese Fraudster Gets 30 Years in Prison
Also: Hollywood Director Jailed for $11M Fraud. This week, a Chinese fraudster got 30 years, Hollywood director jailed for $11M fraud, Florida crypto scam plea, China jailed five in FX case, South Korea fines Bithumb, Thailand hunted mining suspect, Poland arrested SIM swappers, Emurgo planned recovery, South Korea targeted manipulators. First seen on govinfosecurity.com Jump…
-
NDSS Symposium Heads to Seoul in 2027 to Expand Global Cybersecurity Collaboration
DC, United States, June 30th, 2026, CyberNewswire The Internet Society today announced that 2027 Network and Distributed System Security (NDSS) Symposium will take place in Seoul, Republic of Korea, from 2226 March 2027. Recognized as one of the world’s top four cybersecurity research conferences, the NDSS Symposium brings together hundreds of top scholars, academics, and…
-
North Korea-Linked macOS Malware Uses Prompt Injection to Evade AI Analysis
SentinelOne says macOS.Gaslight uses prompt injection to mislead AI-based malware analysis, steal data, and use Telegram for C2. The post North Korea-Linked macOS Malware Uses Prompt Injection to Evade AI Analysis appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-macos-gaslight-malware-ai-prompt-injection/
-
macOS.Gaslight: North Korea-Linked Malware That Tries to Gaslight the Analyst
macOS.Gaslight: DPRK Rust implant for Mac with a prompt injection payload designed to fool AI-based malware analysts. SentinelLabs researchers spotted a Rust-based macOS implant, dubbed macOS.Gaslight, that surfaced in early June after an Apple XProtect update pointed to a VirusTotal sample uploaded on May 22. The binary was undetected by static engines at the time…
-
macOS Backdoor Uses Prompt Injection to Evade AI Triage
SentinelLabs found a North Korea-linked macOS backdoor using prompt injection on AI triage tools First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/macos-gaslight-rust-backdoor/
-
Microsoft Attributes Mastra AI Supply Chain Attack to North Korea
North Korean threat actor Sapphire Sleet has been linked to a supply chain attack targeting Mastra, according to Microsoft security researchers First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/mastra-ai-supply-chain-attack/

