"SEAL weekly stats: Sept. 8-14, 2026" published by SecurityAlliance. #Trend, #ContagiousInterview, #ITWorker, #SINT01 https://radar.securityalliance.org/seal-weekly-stats-sept-8-14-2026
SEAL weekly stats: Sept. 8-14, 2026
radar.securityalliance.org
lazarusholic
@lazarusholic.bsky.social
a big fan of lazarus. https://lazarus.day
"SEAL weekly stats: Sept. 8-14, 2026" published by SecurityAlliance. #Trend, #ContagiousInterview, #ITWorker, #SINT01 https://radar.securityalliance.org/seal-weekly-stats-sept-8-14-2026
SEAL weekly stats: Sept. 8-14, 2026
radar.securityalliance.org
"Now recruiting: North Korea looks abroad for talent in its scheme to infiltrate U.S. companies" published by NBCNews. #News, #ITWorker, #MoneyLaundering https://www.nbcnews.com/tech/security/north-korea-worker-scheme-recruits-abroad-rcna596873
Now recruiting: North Korea looks abroad for talent in its scheme to infiltrate U.S. companies
nbcnews.com
"APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析" published by Qihoo360. #APTC55, #LNK, #LOTL https://mp.weixin.qq.com/s/9ilhH-WUqeNCStDfbrBsrw
APT-C-55(Kimsuky)组织利用伪装安装包植入远控木马的攻击链分析
mp.weixin.qq.com
"Treasury Cracks Down on Transnational Criminal Organization Behind Cyber Scam Operations Targeting Americans" published by USTreasury. #Cryptocurrency, #Sanctions, #MoneyLaundering https://home.treasury.gov/news/press-releases/sb0624
Treasury Cracks Down on Transnational Criminal Organization Behind Cyber Scam Operations Targeting Americans
home.treasury.gov
"OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals" published by Chainalysis. #Sanctions, #MoneyLaundering, #WazirX, #Bybit https://www.chainalysis.com/blog/ofac-sanctions-xinbi-cybercriminal-crypto-marketplace
OFAC and DOJ Strike Xinbi, a Multibillion-Dollar Marketplace for Cybercriminals
chainalysis.com
"Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack" published by MalBeacon. #PyPI, #OtterCandy, #PolinRider https://blog.deception.pro/blog/hok-dprk-polinrider-sep-2026
Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack
blog.deception.pro
"기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장" published by ESTSecurity. #Kimsuky, #LNK, #GitHub, #LOTL https://blog.alyac.co.kr/5777
기능별 C2 서버를 운용하는 Kimsuky 그룹의 새로운 LNK 악성코드 등장
blog.alyac.co.kr
"GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI" published by Google. #Trend, #ITWorker, #MidnightNeptune https://cloud.google.com/blog/topics/threat-intelligence/from-prompting-to-autonomy-the-evolution-of-adversarial-ai
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI
cloud.google.com
"SEAL weekly stats: Sept 1-8, 2026" published by SecurityAlliance. #Trend, #Phishing https://radar.securityalliance.org/seal-weekly-stats-sept-1-2026
SEAL weekly stats: Sept 1-8, 2026
radar.securityalliance.org
"2026년 Kimsuky의 스피어피싱·지속성 전략" published by ENKI. #Kimsuky, #Phishing, #LNK, #GitHub, #Slides, #AsyncRAT https://www.dailysecu.com/form/html/pascon/pdf/2026/KCSCON2026_B-1.pdf
2026년 Kimsuky의 스피어피싱·지속성 전략
dailysecu.com
"Beyond Lazarus: Organization of DPRK Cyber Capabilities" published by KudelskiSecurity. #APT38, #Andariel, #Kimsuky, #CryptoCore, #TEMPHermit, #JadeSleet, #CitrineSleet, #ITWorker, #MoonstoneSleet, #Lazarus https://kudelskisecurity.com/research/beyond-lazarus-organization-of-dprk-cyber-capabilities
Beyond Lazarus: Organization of DPRK Cyber Capabilities
kudelskisecurity.com
"Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve" published by Genians. #Kimsuky, #Phishing, #LNK, #GitHub, #GitPower https://www.genians.co.kr/en/blog/threat_intelligence/ai-agent-opencode
Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve
genians.co.kr
"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors" published by Rapid7. #APT37, #Wateringhole, #HAProxy, #curlRAT https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
rapid7.com
"Contagious Interview steps outside the developer workflow" published by Jamf. #macOS, #ContagiousInterview, #OtterCookie https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers
Contagious Interview steps outside the developer workflow
jamf.com
"Malicious code executed on clone between 2026-08-29 and 2026-09-02" published by BindsNET. #VSCode, #PolinRider, #BindsNET https://github.com/BindsNET/bindsnet/security/advisories/GHSA-6f2q-w3r8-xxhj
Malicious code executed on clone between 2026-08-29 and 2026-09-02
github.com
"North Korean hackers are moving tens of millions on Hyperliquid as Trump pushes to onshore the crypto platform" published by CoinDesk. #Lazarus https://www.coindesk.com/business/2026/08/31/north-korean-hackers-are-moving-tens-of-millions-on-hyperliquid-as-trump-pushes-to-onshore-the-crypto-platform
North Korean hackers are moving tens of millions on Hyperliquid as Trump pushes to onshore the crypto platform
coindesk.com
"SEAL weekly stats: August 25-31, 2026" published by SecurityAlliance. #Trend, #UNC1069 https://radar.securityalliance.org/seal-weekly-stats-august-25-31-2026
SEAL weekly stats: August 25-31, 2026
radar.securityalliance.org
"A malicious npm package hidden three dependencies deep: the ulid-xyz delivery chain" published by SafeDep. #NPM, #FamousChollima https://safedep.io/ulid-xyz-transitive-dependency-delivery-chain
A malicious npm package hidden three dependencies deep: the ulid-xyz delivery chain
safedep.io
"July 2026 Threat Trend Report on APT Attacks (South Korea)" published by Ahnlab. #Trend, #Phishing, #LNK, #GitHub, #AutoIt, #XenoRAT https://asec.ahnlab.com/en/95171
July 2026 Threat Trend Report on APT Attacks (South Korea)
asec.ahnlab.com
"Insights into Suspected DPRK Workers: Red Flags to Look Out For" published by Huntress. #ITWorker, #FamousChollima, #PiKVM, #Guermok https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation
Insights into Suspected DPRK Workers: Red Flags to Look Out For
huntress.com
"Insights into Suspected DPRK Workers: Red Flags to Look Out For" published by Huntress. #ITWorker, #FamousChollima, #PiKVM, #Guermok https://www.huntress.com/blog/huntress-dprk-remote-worker-investigation
Insights into Suspected DPRK Workers: Red Flags to Look Out For
huntress.com
"Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" published by Zscaler. #Kimsuky, #Konni, #macOS, #XenoRAT, #TokenPhantom https://www.slideshare.net/slideshow/hitcon-2026-slide-not-just-spies-anymore-dprk-s-espionage-actors-are-coming-for-your-crypto/289497394
Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto
slideshare.net
"NPM Isn't Prepared For North Korean PolinRider Attack" published by OpenSourceMalware. #GitHub, #NPM, #PolinRider, #NullReceiver https://opensourcemalware.com/blog/polinrider-npm-case-study-dprk-attack
NPM Isn't Prepared For North Korean PolinRider Attack
opensourcemalware.com
"Nation-State Hiring Fraud: Fake IT Workers, Laptop Farms, and Background-Check Blind Spots" published by Abnormal. #ITWorker, #Deepfake https://www.abnormal.ai/blog/nation-state-hiring-fraud
Nation-State Hiring Fraud: Fake IT Workers, Laptop Farms, and Background-Check Blind Spots
abnormal.ai
"North Korea’s Crypt: Hunting Ghosts" published by Bitso. #Phishing, #VSCode https://quetzal.bitso.com/p/north-koreas-crypt-hunting-ghosts
North Korea’s Crypt: Hunting Ghosts
quetzal.bitso.com
"Malicious Rust Crate arrayref Runs a Build-Time Payload" published by SafeDep. #arrayref https://safedep.io/arrayref-proc-macro1-rust-build-time-malware/
Malicious Rust Crate arrayref Runs a Build-Time Payload
safedep.io
"Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack" published by Aikido. #arrayref https://www.aikido.dev/blog/two-popular-rust-crates-arrayref-and-append-only-vec-compromised-in-supply-chain-attack
Two popular Rust crates arrayref and append-only-vec compromised in Supply Chain Attack
aikido.dev
"Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper" published by StepSecurity. #arrayref https://www.stepsecurity.io/blog/arrayref-rust-crate-supply-chain-attack
Rust Supply-Chain Attack: arrayref, internment, and append-only-vec Poisoned by the proc-macro1 Build-Time Dropper
stepsecurity.io
"Supply chain attack on arrayref" published by RustLang. #arrayref https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
Supply chain attack on arrayref
blog.rust-lang.org