Tag: north-korea
-
Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/
-
Crypto CEO accuses North Korea of stealing $387 million from Bitget platform
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses. First seen on therecord.media Jump to article: therecord.media/crypto-ceo-accuses-north-korea-of-387-million-theft
-
The Cyber Express Weekly Roundup: ShinyHunters’ FBI Breach Claim, North Korea’s WaterPlum Campaign, and the EU KIDS Act
Tags: access, advisory, ai, application-security, breach, crypto, cyber, korea, malware, north-koreaThis weekly roundup covers a brazen breach claim against the FBI’s recruitment portal, a multinational advisory exposing North Korea’s fake-recruiter malware operation, a sweeping EU proposal to reshape children’s access to social media, a conversation on application security in the age of AI agents, a short-lived Discord ban in the Philippines, and a multimillion-dollar hot-wallet…
-
North Korean hackers suspected in $351M crypto theft, the largest so far this year
The $351 million theft from crypto exchange Bitget is the latest in a string of high profile hacks targeting the crypto sector. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/25/north-korean-hackers-suspected-in-351m-crypto-theft-the-largest-so-far-this-year/
-
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/
-
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea’s Lazarus Group may be involved as investigators examine the breach in detail. First seen on hackread.com Jump to article: hackread.com/bitget-hack-suspects-north-korea-lazarus-group/
-
Bitget Confirms $351.6 Million Hack, Suspects North Korea’s Lazarus Group
Bitget confirms a $351.6 million theft, suspends withdrawals and says North Korea’s Lazarus Group may be involved as investigators examine the breach in detail. First seen on hackread.com Jump to article: hackread.com/bitget-hack-suspects-north-korea-lazarus-group/
-
Breach Roundup: Thousands of AI Relays Hide China Users
Tags: ai, breach, china, cisa, cve, cybercrime, data, data-breach, flaw, google, jobs, north-korea, russia, scam, vpnAlso, CISA Ends Weekly CVE Bulletin After 22 Years, Check Point VPN Flaw Exploited. This week: AI relay servers connect to China, CISA ends weekly CVE bulletin, cybercriminal guilty pleas and sentences, drug dealers hijack Google Maps, Russian Burger King customers’ data leaked, North Korean fake job scams, SectopRAT, a Check Point VPN flaw and…
-
Operation Conflict Compass Deploys VelvetCake PowerShell Malware Through Malicious LNK Files
Tags: cyber, cyberespionage, intelligence, korea, malicious, malware, north-korea, powershell, russia, threat, ukraine, windowsNorth Korea-linked threat actor Konni has launched a targeted cyberespionage operation against Ukraine-focused entities using malicious Windows shortcut files disguised as PDF documents. The campaign, tracked by SOCRadar Threat Research Unit as Operation Conflict Compass, deploys a modular PowerShell malware family dubbed VelvetCake to collect intelligence on the Russia-Ukraine war. The activity appears designed to…
-
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-waterplum-30000/
-
North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
North Korean hackers are using fake Terraform job tests to deploy macOS backdoors and target developer access to cloud infrastructure. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-north-korean-terraform-malware/
-
Contagious Interview: 30,000 devices infected by a fake job interview
North Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from Australia and Germany published a joint advisory about a group called WaterPlum, better known as Contagious Interview.…
-
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency, First…
-
North Korea’s job interview scam runs both ways
Attackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/21/north-korean-hackers-contagious-interview-defenses/
-
North Korea’s Hangro VPN Certificate Exposes Internal Network and Russia-Linked Infrastructure
North Korea’s Hangro VPN and mail platform has deployed a new certificate hierarchy that exposes an apparent cross-border management environment spanning systems in Pyongyang and Russia’s Far East. The certificate’s Subject Alternative Name field lists the platform’s publicly exposed servers alongside a carrier-grade NAT address, offering an unusual glimpse into how the service may be…
-
Hackers Weaponize Terraform Lock Files to Infect DevOps Engineers With macOS Backdoors
North Korea-linked threat actor TraderTraitor has expanded its developer-focused intrusion activity beyond cryptocurrency targets, using weaponized Terraform lock files in fake job-interview repositories to infect DevOps engineers with macOS backdoors. SentinelOne identified an Indian IT services provider compromised with the same FLATROOF and ROOFDECK implants previously linked to the April 2026 KelpDAO-LayerZero attack. The campaign…
-
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.Cybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use…
-
North Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to North Korea. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/north-korean-waterplum-hackers-infected-30-000-devices-worldwide/
-
North Korean WaterPlum Hackers Target IT Professionals With Fake Job Interviews to Steal Crypto
North Korean threat actors, known as WaterPlum (also referred to as Contagious Interview), have infected at least 30,000 devices in over 100 countries by luring software developers and IT professionals into malicious job interviews. This campaign specifically targets web developers, freelancers, blockchain specialists, and cryptocurrency professionals. The attackers use persuasive recruitment messages that mimic legitimate…
-
North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum”, a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies. First seen on therecord.media Jump to article: therecord.media/north-korean-hackers-infect-thousands-of-devices-waterplum-scheme
-
International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data
The U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. First seen on cyberscoop.com Jump to article: cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/
-
Nations take action on North Korean IT workers after UN report
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study. First seen on therecord.media Jump to article: therecord.media/nations-take-action-on-north-korean-it-worker-schemes
-
Nordkoreanische Cyberkriminelle bestehlen IT-Fachleute auf Jobsuche
Sicherheitsbehörden warnen vor einer Cybergruppe aus Nordkorea, die gezielt IT-Spezialisten angreift. Was hinter der Kampagne Contagious Interview steckt. First seen on golem.de Jump to article: www.golem.de/news/cybercrime-nordkoreanische-cyberkriminelle-bestehlen-it-fachleute-auf-jobsuche-2609-213184.html
-
North Korean IT Workers Pay People to Sit Through Job Interviews While They Control the Computer
North Korean IT-worker operators are recruiting foreign nationals to sit on camera during remote job interviews. At the same time, the real candidate provides answers, completes coding tasks, or remotely controls the proxy’s computer, according to new research from Silent Push. The campaign turns ordinary job seekers into identity and payment intermediaries, creating a direct…
-
Cyber Op Targets South Korean Media & Automotive Sectors
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive
-
North Korea-linked Hackers Hide a Backdoor Inside HAProxy
North Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load balancing software running at the edge of two South Korean companies’ networks. Rapid7’s…
-
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea’s Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korea-lazarus-six-cyber/
-
Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authenticated payload delivery, and AI-generated decoy documents linked to the OpenCode coding agent. Genians Security Center analyzed 13 malicious LNK samples collected between August 11 and August 19, 2026. The files were delivered in ZIP archives…

