STARDUST CHOLLIMA: North Korean Hacking Group
STARDUST CHOLLIMA is another alias for the North Korean threat group also known as Sapphire Sleet and UNC1069, involved in cryptocurrency theft…
STARDUST CHOLLIMA is another alias for the North Korean threat group also known as Sapphire Sleet and UNC1069, involved in cryptocurrency theft…
CageyChameleon is a North Korean cyber group associated with cryptocurrency theft and malware campaigns, overlapping with Sapphire Sleet.
CryptoCore is a North Korean threat actor focused on cryptocurrency theft, also known as BlueNoroff and Sapphire Sleet.
typo-crypto is a malicious npm package designed to impersonate crypto-js, first published in March 2025. It contained a trojanized file (core.js) and…
A malvertising operation named SourTrade, active since late 2024, uses victims' browsers to build a Windows executable from components served across multiple…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
Group-IB has identified a new macOS infostealer, ClickLock Stealer, that uses a coercive technique to force victims to enter their login password.…
Tonkeeper is a cryptocurrency wallet targeted by OkoSpyware through browser title matching.
Trezor Suite is the official desktop application for managing Trezor hardware wallets. It was targeted by the SeedHunter module for phishing recovery…
Ledger Wallet is a desktop application for Ledger hardware wallets. It was targeted by SeedHunter for injecting fake recovery pages.