Smile, You’re on Camera. Part 2: Hiring Lazarus APT’s IT Workers in a Fake DeFi Startup post, augustus 12, 2026augustus 17, 2026 Back in December, we were the first ever to fully record the Famous Chollima infiltration cycle. From recruiting collaborators to help them land jobs at Western companies, to forging documents, shipping laptops to facilitators’ houses, and even using AI tools for live assistance and translation during interviews. During that investigation,… Continue Reading
ClickFix attack pushes macOS infostealer for crypto theft attacks post, augustus 6, 2026augustus 17, 2026 A Go-based malware delivered in ClickFix attacks targeting macOS users is stealing cryptocurrency assets, browser-stored passwords, Apple Keychain data, and cached credentials. The malware can intercept and redirect transactions with various cryptocurrencies. Although it can empty wallets entirely, it can also calculate the total value of a transaction to determine… Continue Reading
DPRK-Linked macOS Malvertising Uses Fake Updates to Deliver Crypto-Stealing Malware post, juli 31, 2026augustus 17, 2026 Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Contagious Interview campaign. The defining aspect of the attack is… Continue Reading
Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images post, juli 17, 2026juli 20, 2026 North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. “Any user who ran the project ended up with a four-stage payload aligned with OtterCookie: a browser… Continue Reading
New Lazarus APT Campaign: “Mach-O Man” macOS Malware Kit Hits Businesses post, april 30, 2026mei 1, 2026 The recent wave of ClickFix attacks has introduced several new ways to compromise users, establishing itself as a technique that is likely here to stay. We have observed Lazarus Group using this method to distribute a range of malware, from well-known families to more unusual variants such as PyLangGhostRAT, a… Continue Reading
North Korea’s Lazarus Targets macOS Users via ClickFix post, april 24, 2026april 29, 2026 North Korea’s Lazarus Group is using ClickFix attacks to launch cyberattacks using novel macOS malware. That’s according to security vendor Any.Run, which on April 21 published research concerning a new nation-state threat campaign. Authored by offensive security expert and Birmingham Cyber Arms founder Mauro Eldritch, the report covers a wave… Continue Reading
GitLab Threat Intelligence Team reveals North Korean tradecraft post, februari 19, 2026februari 23, 2026 Gain threat intelligence about North Korea’s Contagious Interview and fake IT worker campaigns and learn how GitLab disrupted their operations. Continue Reading
Noord-Koreaanse dreigingsactoren richten zich op Oekraïense overheidsinstanties post, mei 26, 2025 In februari 2025 begon TA406, een door Noord-Korea gesponsorde dreigingsactor, zich te richten op overheidsinstanties in Oekraïne. Zowel credential harvesting als malware werden ingezet in phishingcampagnes. Het vermoedelijke doel van deze campagnes is het verzamelen van inlichtingen over het verloop van de Russische invasie. TA406 overlapt met activiteiten die door… Continue Reading
North Korean Hackers Deploy BeaverTail Malware via 11 Malicious npm Packages post, april 5, 2025april 7, 2025 The North Korean threat actors behind the ongoing Contagious Interview campaign are spreading their tentacles on the npm ecosystem by publishing more malicious packages that deliver the BeaverTail malware, as well as a new remote access trojan (RAT) loader. “These latest samples employ hexadecimal string encoding to evade automated detection systems and… Continue Reading
Bybit Confirms Record-Breaking $1.5 Billion Crypto Heist in Sophisticated Cold Wallet Attack post, februari 22, 2025februari 24, 2025 Cryptocurrency exchange Bybit on Friday revealed that a “sophisticated” attack led to the theft of over $1.5 billion worth of cryptocurrency from one of its Ethereum cold (offline) wallets, making it the largest ever single crypto heist in history. “The incident occurred when our ETH multisig cold wallet executed a transfer to… Continue Reading