Tag: north-korea
-
Contagious Interview Operators Move Beyond Git Hooks With Trojanized Mac Applications
North Korea-linked Contagious Interview operators have expanded their developer-targeting malware delivery operation beyond booby-trapped Git hooks and coding repositories, using trojanized macOS applications distributed as disk images and installer packages. Jamf Threat Labs identified 14 malicious DMG and PKG samples impersonating legitimate Mac software, all of which ultimately deliver an OtterCookie-aligned JavaScript implant designed for…
-
Podcast: North Korea’s $1.46 Billion Heist: Lazarus, Kimsuky, and Andariel Explained
Sep 2, 2026 Podcast: North Korea’s $1.46 Billion Heist: Lazarus, Kimsuky, and Andariel Explained Tova Dvorin (00:00) Welcome back to The Cyber Resilience Brief, a SafeBreach podcast. I’m your host, Tova Dvorin. Today, we’re diving into one of the most… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/podcast-north-koreas-1-46-billion-heist-lazarus-kimsuky-and-andariel-explained/
-
The Ongoing Spread of North Korean Worker Scams
The notorious North Korean IT worker scams continue to expand beyond U.S. borders and into fields other than IT, a worrying notion in a complex and vast operation that brings as much as $800 million a year to the rogue nation. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-ongoing-spread-of-north-korean-worker-scams/
-
Nisos DPRK Investigation Featured on NBC News
Nisos Nisos DPRK Investigation Featured on NBC News Blog Nisos Featured on NBC News for North Korean Employment Fraud Investigation NBC News covered our investigation into industrial-scale infiltration of US companies. Here’s what it reveals about the future of identity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/nisos-dprk-investigation-featured-on-nbc-news/
-
North Korea-linked IT Workers Are Getting Hired Inside Western Companies
Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS…
-
Nordkoreanischer Jobbetrug erfasst Gesundheitswesen und Vertrieb
Tags: north-koreaMit Nordkorea in Verbindung stehende Akteure bewerben sich laut aktuellen Untersuchungen inzwischen nicht mehr nur auf IT-Stellen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/nordkorea-jobbetrug
-
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession.The ongoing insider threat is part of what has been described as the…
-
North Korean remote workers are broadening their job hunt beyond IT
North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/28/north-korean-remote-workers-jobs-sales-and-marketing/
-
North Korean remote workers are broadening their job hunt beyond IT
North Korean (DPRK) remote workers are expanding their job searches beyond IT, according to Huntress. Recent investigations have identified suspected DPRK workers employed in … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/28/north-korean-remote-workers-jobs-sales-and-marketing/
-
Breach Roundup: A Call for Cyber Defense Collective Action
e=4>This week: a call for cyber defense, OpenAI banned Russian ChatGPT accounts, critical Gitea flaw, U.K. airport passenger data theft, North Korean remote workers, Barcelona police data, Norway services hit by DDoS, Taiwan charged 9 over AI server exports and Nigeria advanced a sovereign cloud push. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/breach-roundup-call-for-cyber-defense-collective-action-a-32673
-
Red Flags That Expose Fake North Korean IT Workers
North Korean operatives posing as IT workers are improving their tactics, but researchers say there are still ways to spot them before they do damage. First seen on darkreading.com Jump to article: www.darkreading.com/insider-threats/red-flags-expose-fake-north-korean-it-workers
-
North Korean Hackers Target Healthcare: What You Need to Know
North Korean cyberattacks reveal how trusted identities and workflows create healthcare cybersecurity risk, and how security teams can test them. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/north-korean-hackers-target-healthcare-what-you-need-to-know/
-
Huntress Uncovers Five Cases of North Korean Operatives Posing as Remote IT, Sales and Healthcare Workers
Cybersecurity firm Huntress has confirmed five separate incidents this year in which suspected North Korean operatives were successfully hired into legitimate organisations under false identities, in a wave of activity researchers say shows how the country’s so-called >>remote IT worker<< scheme has expanded well beyond IT roles. The cases, disclosed in a new advisory, involved…
-
North Korean Hackers Hide AnyDesk on Victim PCs to Maintain Secret Remote Access
Tags: access, cyber, email, hacker, korea, malicious, north-korea, phishing, powershell, software, spear-phishing, theft, windowsNorth Korea-linked Kimsuky operators have targeted organizations in South Korea and Japan with spear-phishing campaigns that install and conceal AnyDesk, giving attackers persistent, interactive remote access while blending into legitimate software activity. The operation combines OneDrive-hosted lures, malicious Windows shortcut files, scheduled-task persistence, PowerShell payloads, and email theft across Thunderbird, Outlook, and Gmail. The archives…
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
North Korean Hackers Tied to Rust Supply Chain Attack
Cybersecurity researchers have linked a malicious backdoor in compromised Rust packages to previous North Korean supply chain attacks First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/north-korean-rust-supply-chain/
-
Nordkorea flutet den Jobmarkt mehr denn je
Tags: north-koreaWährend Personalabteilungen noch mit klassischen Lebenslauf-Checks arbeiten, hat Nordkorea die Bewerbung längst industrialisiert. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/nordkorea-jobmarkt
-
Hired, Fired, Extorted: What North Korean IT Workers Reveal About Hiring Fraud
Hiring fraud costs enterprises up to $1.99M a year before OFAC exposure. North Korean IT worker operations show why the numbers are accelerating. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/hired-fired-extorted-what-north-korean-it-workers-reveal-about-hiring-fraud/
-
Alert: Unpatched Fortinet Devices Fall to Gunra Ransomware
Tags: access, cybersecurity, firewall, fortinet, government, group, infrastructure, korea, north-korea, ransomware, vpnUS and South Korea Tie Initial Access to Unpatched Firewalls and VPN Gateways. Critical infrastructure organizations running unpatched firewalls and VPN gateways – including Fortinet gear not updated since early 2025 – and getting hit hard by a ransomware group with possible ties to the North Korean government, warns a joint U.S.-South Korean cybersecurity alert.…
-
North Korean remote IT staffer worked for US government agency, says FBI
The investigation shows that North Koreans are able to infiltrate government agencies, as well as private organizations and crypto exchanges. First seen on techcrunch.com Jump to article: techcrunch.com/2026/08/11/north-korean-remote-it-staffer-worked-for-us-government-agency-says-fbi/
-
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California driver’s license and a New York…
-
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea’s state hackers are no longer content to type prompts into public chatbots. One of the country’s main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.South Korean security firm…
-
North Korean Hackers Explore AI Transcription for Stolen Calls and Meetings
Tags: ai, breach, cyber, hacker, intelligence, korea, malicious, north-korea, phishing, powershell, spear-phishing, windowsNorth Korea-linked Kimsuky operators are expanding their artificial intelligence capabilities, with newly observed evidence showing experimentation with local large language models. Retrieval-augmented generation, AI agents, and speech-to-text tooling that could accelerate analysis of stolen calls, meetings, and documents. The operation retains Kimsuky’s established use of spear-phishing lures, malicious Windows shortcut files, PowerShell loaders, and Git-based…
-
North Korea linked to new NullReceiver C2 technique
First seen on scworld.com Jump to article: www.scworld.com/brief/north-korea-linked-to-new-nullreceiver-c2-technique
-
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe. First seen on wired.com Jump to article: www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/
-
Google Warns Open-Source Attacks Will Reach New Heights
Google Says Open-Source Compromises Are Easier to Scale and Replicate. Compromising the open-source supply chain is easy to do and spreads more quickly than traditional supply-chain attacks, making it a lucrative tactic that will continue to expand, warned Google. One of the largest open-source supply-chain attacks involved a North Korean threat actor. First seen on…
-
Amazon Links Four npm Supply-Chain Attacks to North Korea’s Sapphire Sleet
Amazon linked four npm supply-chain attacks to North Korea’s Sapphire Sleet, exposing the security risks posed by compromised maintainer accounts. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-amazon-npm-attacks-sapphire-sleet/
-
North Korea Rebuilt Its Antivirus Using ClamAV and Gave It Four Different Names
North Korea’s national antivirus appears to have quietly pivoted to ClamAV’s open”‘source engine, recompiled it, and shipped it under four different domestic product names underscoring Pyongyang’s reliance on foreign code to secure tightly controlled networks while obscuring the software’s true origin. ClamAV is a widely used open”‘source antivirus engine maintained by the Cisco Talos team,…

