Tag: korea
-
Nations take action on North Korean IT workers after UN report
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study. First seen on therecord.media Jump to article: therecord.media/nations-take-action-on-north-korean-it-worker-schemes
-
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and First seen on thehackernews.com Jump to…
-
Breach Roundup: China Calls for Stronger AI Oversight
Also, Spain’s First AI Agent-Linked Data Breach, NightmareStresser Domains Seized. This week: a call for stronger AI oversight in China, an AI agent-linked breach in Spain, Cisco active exploits, Check Point patched flaws. NightmareStresser seized – again! South Korea data breach fines, AI made BEC attacks worse. An Android Trojan, an exploited Pixel flaw and…
-
North Korea-linked Hackers Hide a Backdoor Inside HAProxy
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s…
-
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea’s Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/
-
Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authenticated payload delivery, and AI-generated decoy documents linked to the OpenCode coding agent. Genians Security Center analyzed 13 malicious LNK samples collected between August 11 and August 19, 2026. The files were delivered in ZIP archives…
-
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and coding repositories, using trojanized macOS applications distributed as disk images and installer packages. Jamf Threat Labs identified 14 malicious DMG and PKG samples impersonating legitimate Mac software, all of which ultimately deliver an OtterCookie-aligned JavaScript implant designed for…
-
Podcast: North Korea’s $1.46 Billion Heist: Lazarus, Kimsuky, and Andariel Explained
Sep 2, 2026 Podcast: North Korea’s $1.46 Billion Heist: Lazarus, Kimsuky, and Andariel Explained Tova Dvorin (00:00) Welcome back to The Cyber Resilience Brief, a SafeBreach podcast. I’m your host, Tova Dvorin. Today, we’re diving into one of the most… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/podcast-north-koreas-1-46-billion-heist-lazarus-kimsuky-and-andariel-explained/
-
North Korea-linked IT Workers Are Getting Hired Inside Western Companies
Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS…
-
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.The ongoing insider threat is part of what has been described as the…
-
South Korean startup platform breach exposes key management failures
A breach at South Korea’s government-backed startup platform exposed encrypted personal data after an encryption key was included in an API. Penta Security explains why encryption keys must be securely managed and kept separate from the data they protect. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korean-startup-platform-breach-exposes-key-management-failures/
-
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
Tags: access, cyber, email, hacker, korea, malicious, north-korea, phishing, powershell, software, spear-phishing, theft, windowsNorth Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives…
-
Cryptohack Roundup: Harmony’s Post-Exploit Blockchain Rollback
Also: Fake Web3 Interview Led to Wallet Theft, Delio CEO’s 15-Yr Sentence. This week, Harmony to roll back blockchain after exploit, Delio CEO sentenced to 15 years in South Korea, an alleged Ponzi promoter deported to the United States, SafePal and Trezor customers’ data exposed, and attackers exploited a Mac flaw to mine Monero. First…
-
Alert: Unpatched Fortinet Devices Fall to Gunra Ransomware
Tags: access, cybersecurity, firewall, fortinet, government, group, infrastructure, korea, north-korea, ransomware, vpnUS and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways. Critical infrastructure organizations running unpatched firewalls and VPN gateways – including Fortinet gear not updated since early 2025 – and getting hit hard by a ransomware group with possible ties to the North Korean government, warns a joint U.S.-South Korean cybersecurity alert.…
-
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Tags: attack, breach, cybersecurity, exploit, finance, flaw, fortinet, government, healthcare, infrastructure, intelligence, korea, network, ransomware, serviceCybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world.Targets of these attacks include healthcare and public health, financial services, government services and facilities, and professional and nonprofit services.”Gunra is another variant in the ongoing trend of First seen on thehackernews.com…
-
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea’s National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/us-warns-of-gunra-ransomware-attacks-against-government-critical-infrastructure/
-
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned. First seen on therecord.media Jump to article: therecord.media/ransomware-south-korea-fbi-gunra
-
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.South Korean security firm…
-
North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings
Tags: ai, breach, cyber, hacker, intelligence, korea, malicious, north-korea, phishing, powershell, spear-phishing, windowsNorth Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling that could accelerate analysis of stolen calls, meetings, and documents. The operation retains Kimsuky’s established use of spear-phishing lures, malicious Windows shortcut files, PowerShell loaders, and Git-based…
-
North Korea linked to new NullReceiver C2 technique
First seen on scworld.com Jump to article: www.scworld.com/brief/north-korea-linked-to-new-nullreceiver-c2-technique
-
South Korea’s government overtakes telcos as top cyber attack target
Kaspersky researcher Sojun Ryu says ransomware crews have joined nation-state groups in going after South Korean organisations, as traces of LLM output start turning up inside malware First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366647735/South-Koreas-government-overtakes-telcos-as-top-cyber-attack-target
-
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-amazon-npm-attacks-sapphire-sleet/
-
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open”‘source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin. ClamAV is a widely used open”‘source antivirus engine maintained by the Cisco Talos team,…
-
Korea’s Largest Telco KT Fined $38m After Femtocell Campaign
Korean telco KT has been fined $39m for a year-long breach linked to femtocell compromise First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/koreas-largest-telco-kt-fine-39m/
-
North Korea’s APT Capabilities Are No Longer State-Exclusive
Tags: access, apt, cyber, finance, group, hacker, infrastructure, korea, lazarus, malware, military, north-korea, ransomware, skillsAhnLab Found Shared Malware, SSH Keys and Infrastructure Across Two Campaigns. Shared malware, infrastructure and access methods link Lazarus Group to Gunra ransomware activity, while former North Korean military hackers allegedly used state-trained skills to steal bank funds, exposing cyber capability diffusion and blowback inside the regime. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/north-koreas-apt-capabilities-are-no-longer-state-exclusive-a-32392
-
South Korea Warns of State-Backed Watering Hole Attacks
South Korea warned that nation-state actors are using phishing and compromised websites to silently infect citizens and businesses. South Korea agencies (The National Intelligence Service, the National Police Agency, the Korea Internet & Security Agency, and the Financial Security Institute) jointly published an advisory warning that a state-backed hacking group is actively targeting South Korean…
-
Amazon pins multiple open source compromises on North Korea
Amazon threat researchers found one threat actor behind four distinct open source compromises, including the March 2026 incident affecting the axios NPM library First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366646561/Amazon-pins-multiple-open-source-compromises-on-North-Korea
-
AWS Blames North Korean Group for Axios and Other npm Supply Chain Attacks
AWS has linked North Korea to the axios campaign to other attacks on npm libraries First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/aws-north-korea-axios-npm-supply/
-
South Korea fines telco giant KT $39 million for customer data breach
South Korea’s Personal Information Protection Commission (PIPC) has fined telecommunications giant KT Corporation KRW 53.979 billion ($39 million) over data protection violations. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/south-korea-fines-telco-giant-kt-39-million-for-customer-data-breach/
-
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign.The defining aspect of the attack is that bogus macOS software…

