Researchers Pose as Fake Crypto Startup to Hire Suspected North Korean IT Workers
Security researchers created a fictitious cryptocurrency startup and hired three individuals they believe were North Korean IT operatives, as part of an…
Security researchers created a fictitious cryptocurrency startup and hired three individuals they believe were North Korean IT operatives, as part of an…
Chrome Remote Desktop is a remote access tool that allows users to control computers remotely. A suspected North Korean operative installed it…
2fa.cn is a tool used for passing two-factor authentication codes between operators. It was observed in the undercover operation, replacing previously used…
North Korea's Kimsuky hacking group, operating under the Reconnaissance General Bureau, has been assembling an offline artificial intelligence (AI) stack on its…
Cybersecurity researchers have uncovered a new evolution of the EtherHiding blockchain-based command-and-control (C2) technique, dubbed NullReceiver, which conceals the C2 server IP…
Microsoft has disclosed a cyber espionage campaign, tracked as CaptiveCrunch, that abuses hijacked hotel Wi-Fi captive portals to deliver a remote access…
Russian threat actors linked to the exploitation of a Zimbra vulnerability have been observed exploiting CVE-2026-42897, a cross-site scripting (XSS) flaw in…
Iranian state-backed hacking group Nimbus Manticore (also known as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been linked to…
Nimbus Manticore, also tracked as GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549, is an Iranian state-backed hacking group known for…
The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign involving a malicious program disguised as a Notepad++…