"A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide" published by Wired. #News, #ContagiousInterview, #ITWorker
https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/
https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/
WIRED
A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide
For nearly two years, researcher Vangelis Stykas has maintained access to North Korean hackers’ servers. His work shows they pulled off intrusions in a shocking number of systems across the globe.
"Xctdoor와 과거 CRAT 공격 사례의 연관성 분석 (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
https://asec.ahnlab.com/ko/94846
https://asec.ahnlab.com/ko/94846
ASEC
Xctdoor와 과거 CRAT 공격 사례의 연관성 분석 (Larva-26005) - ASEC
Xctdoor와 과거 CRAT 공격 사례의 연관성 분석 (Larva-26005) ASEC
"Two arrested in Wonsan for smishing, voice phishing crimes targeting donju" published by DailyNK. #News
https://www.dailynk.com/english/wonsan-smishing-voice-phishing-donju-arrests/
https://www.dailynk.com/english/wonsan-smishing-voice-phishing-donju-arrests/
North Korea News — Daily NK | Latest DPRK Updates 2026
Two arrested in Wonsan for smishing, voice phishing crimes targeting donju
Two IT graduates trained by the state used smishing texts and fake detention calls to steal savings from donju in Wonsan, sources say.
"Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)" published by Ahnlab. #CVE20178291, #Phishing, #LNK, #Xctdoor, #CRAT, #Larva26005, #Hansom
https://asec.ahnlab.com/en/94847
https://asec.ahnlab.com/en/94847
ASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) - ASEC
Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005) ASEC
"AI를 공격 체계에 접목하는 김수키, 미끼 문서 제작부터 로컬 LLM 구축까지" published by Genians. #Kimsuky, #Phishing, #LNK, #AsyncRAT, #GitPower
https://www.genians.co.kr/blog/threat_intelligence/kimsuky_ai_llm
https://www.genians.co.kr/blog/threat_intelligence/kimsuky_ai_llm
www.genians.co.kr
AI를 공격 체계에 접목하는 김수키, 미끼 문서 제작부터 로컬 LLM 구축까지
생성형 AI로 제작한 미끼 문서와 GitHub·GitLab 기반 C2를 활용하는 김수키(Kimsuky)의 'Operation GitPower' 공격이 포착되었습니다.
"Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM" published by Genians. #Kimsuky, #Phishing, #LNK, #AsyncRAT, #GitPower
https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm
www.genians.co.kr
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM
Operation GitPower, a Kimsuky campaign, uses AI-generated lure documents and GitHub/GitLab-based C2 infrastructure to deliver malicious payloads.
"SMILE, YOU'RE ON CAMERA!" published by Bitso. #Slides, #ITWorker, #FamousChollima
https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Heiner%20Garc%C3%ADa%2C%20Mauro%20Eldritch%20-%20Smile%2C%20you%27re%20on%20camera%20Livestreaming%20from%20North%20Korea%27s%20IT%20workers%20laptop%20farm%20-%20Are%20v2.pdf
https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Heiner%20Garc%C3%ADa%2C%20Mauro%20Eldritch%20-%20Smile%2C%20you%27re%20on%20camera%20Livestreaming%20from%20North%20Korea%27s%20IT%20workers%20laptop%20farm%20-%20Are%20v2.pdf
"Cracking North Korea’s Information Control" published by JDT. #Slides, #OpSec
https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20JDT%20-%20Cracking%20North%20Korea%27s%20Information%20Control%20How%20Smugglers%2C%20Defectors%2C%20and%20Technologists%20are%20Breaking%20Open%20the%20World%27s%20Most%20Locked-D.pdf
https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20JDT%20-%20Cracking%20North%20Korea%27s%20Information%20Control%20How%20Smugglers%2C%20Defectors%2C%20and%20Technologists%20are%20Breaking%20Open%20the%20World%27s%20Most%20Locked-D.pdf
"Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup" published by AnyRun. #ITWorker, #FamousChollima
https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two
https://any.run/cybersecurity-blog/lazarus-group-it-workers-investigation-part-two
any.run
Smile, You’re on Camera! Part 2: Lazarus IT Workers Exposed
See what happened after suspected Lazarus-linked IT workers were hired, from forged identities and AI tools to remote access and supporting infrastructure.
"Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads" published by Sonatype. #NPM, #ContagiousInterview, #NullReceiver
https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads
https://www.sonatype.com/blog/six-npm-packages-use-ethereum-transactions-to-retrieve-malicious-payloads
Sonatype
Six npm Packages Use Ethereum Transactions to Retrieve Malicious Payloads
Malicious npm packages used Ethereum transactions to retrieve a payload, linking hijacked and newly published packages to DPRK-associated malware activity.
"Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack" published by Checkpoint. #DreamJob, #Troy, #FudModule, #Lazarus, #MISTPEN, #CVE202668820, #ForestTiger
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
https://research.checkpoint.com/2026/shattering-the-dream-when-a-job-offer-becomes-a-zero-day-attack/
Check Point Research
Shattering the Dream - When a Job Offer Becomes a Zero-Day Attack - Check Point Research
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the aerospace and aviation…
"North Korean Crypto-to-Fiat Activity" published by RUSI. #Cryptocurrency, #Sanctions, #MoneyLaundering
https://www.rusi.org/explore-our-research/publications/research-papers/north-korean-crypto-fiat-activity
https://www.rusi.org/explore-our-research/publications/research-papers/north-korean-crypto-fiat-activity
www.rusi.org
North Korean Crypto-to-Fiat Activity
North Korea exploits virtual asset-to-fiat conversion to launder stolen cryptocurrency, fuelling WMD programs. The paper offers risk mitigation strategies.
"Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware" published by KudelskiSecurity. #ITWorker, #MoneyLaundering https://kudelskisecurity.com/research/inside-north-koreas-cybercrime-ecosystem-fake-it-workers-gambling-networks-and-malware
Kudelskisecurity
Inside North Korea’s Cybercrime Ecosystem: Fake IT Workers, Gambling Networks and Malware - Kudelski Security Research Center
Aug 12, 2026 - Clifford -
"FBI investigating North Korean remote IT staffer working for US agency" published by FederalNewsNetwork. #News, #ITWorker https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency
Federal News Network
FBI investigating North Korean remote IT staffer working for US agency | Federal News Network
Experts say the incident highlights potential gaps in government and industry vetting processes, especially for jobs like IT support work.
"Inside North Korea’s Operation to Conquer the American Job Market" published by WSJ. #News, #ITWorker
https://www.wsj.com/business/media/inside-north-koreas-operation-to-conquer-the-american-job-market-93729962
https://www.wsj.com/business/media/inside-north-koreas-operation-to-conquer-the-american-job-market-93729962
The Wall Street Journal
Inside North Korea’s Operation to Conquer the American Job Market
Watch how Pyongyang’s scheme to generate $800 million a year works.
"What’s It Like to Hire a North Korean ‘IT Worker’? I Interviewed One" published by Unchained. #ITWorker
https://unchainedcrypto.com/what-its-like-to-interview-a-north-korean-crypto-dev-applying-for-a-job/
https://unchainedcrypto.com/what-its-like-to-interview-a-north-korean-crypto-dev-applying-for-a-job/
Unchained
What’s It Like to Hire a North Korean ‘IT Worker’? I Interviewed One
North Korean “developers” who are really hackers have stolen an estimated $6 billion in crypto. I interviewed one for a job — and found this one question could put a stop to it all.
"Bybit Sues North Korea and Lazarus Group, Secures Preliminary Injunction Freezing Stolen Assets in Landmark Crypto Asset Recovery Effort" published by Bybit. #Lazarus, #Bybit
https://www.bybit.com/en/press/post/bybit-sues-north-korea-and-lazarus-group-secures-preliminary-injunction-freezing-stolen-assets-in-landmark-crypto-asset-recovery-effort-bb55bb16f1710f487aa
https://www.bybit.com/en/press/post/bybit-sues-north-korea-and-lazarus-group-secures-preliminary-injunction-freezing-stolen-assets-in-landmark-crypto-asset-recovery-effort-bb55bb16f1710f487aa
Bybit
Bybit Sues North Korea and Lazarus Group, Secures Preliminary Injunction Freezing Stolen Assets in Landmark Crypto Asset Recovery…
Lawsuit accuses North Korea and Lazarus Group of orchestrating the $1.5 billion theft, as court-ordered asset freeze supports recovery efforts and Bybit expands collaboration with law enforcement and industry partners to strengthen accountability for crypto…
"From fake interview to signed ClickOnce: inside a three-payload Windows chain" published by HaveIBeenSquatted. #Phishing, #NeedleStealer
https://haveibeensquatted.com/blog/from-fake-interview-to-signed-clickonce-three-payload-windows-chain
https://haveibeensquatted.com/blog/from-fake-interview-to-signed-clickonce-three-payload-windows-chain
Have I Been Squatted
Signed ClickOnce delivers two stealers and RAT - Have I Been Squatted
Fake Web3 interview campaign delivering signed ClickOnce, NeedleStealer, a Rust stealer, and a Go hVNC RAT on Windows in July 2026.
"DPRK's Contagious Interview campaign is still running" published by Moonlock. #macOS, #ContagiousInterview, #OtterCookie
https://x.com/moonlock_lab/status/2088333062153138563
https://x.com/moonlock_lab/status/2088333062153138563
X (formerly Twitter)
Moonlock Lab (@moonlock_lab) on X
1/ DPRK's Contagious Interview campaign is still running, the infrastructure is rotating often, and the payload is aimed at Mac users (among others).
We analyzed some stages of OtterCookie chain. The malware increasingly looks like it was written with AI.…
We analyzed some stages of OtterCookie chain. The malware increasingly looks like it was written with AI.…
"Meet my latest North Korean applicant" published by tanuki42. #ITWorker, #ContagiousTrader
https://x.com/tanuki42_/status/2088278343653413254
https://x.com/tanuki42_/status/2088278343653413254
X (formerly Twitter)
tanuki42 (@tanuki42_) on X
1/ I think I found patient zero for COVID-19.
Meet my latest North Korean applicant @hodlwarden ("Ming Cheng"). Ming had a mysterious 3 year employment gap on his resume from 2018-2021 which initially raised some concerns, but then he explained he was receiving…
Meet my latest North Korean applicant @hodlwarden ("Ming Cheng"). Ming had a mysterious 3 year employment gap on his resume from 2018-2021 which initially raised some concerns, but then he explained he was receiving…