UNC5342 (Contagious Interview) Threat Group
UNC5342, also known as Contagious Interview, is a North Korean-linked threat actor cluster that traditionally uses fake job interviews to deliver malware.…
UNC5342, also known as Contagious Interview, is a North Korean-linked threat actor cluster that traditionally uses fake job interviews to deliver malware.…
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake…
Amazon Threat Intelligence has attributed the September 2025 hijack of the popular npm packages debug and chalk to North Korea's Sapphire Sleet…
STARDUST CHOLLIMA is another alias for the North Korean threat group also known as Sapphire Sleet and UNC1069, involved in cryptocurrency theft…
Alluring Pisces is a North Korean threat actor known for social engineering and supply chain attacks, linked to the Sapphire Sleet cluster.
CageyChameleon is a North Korean cyber group associated with cryptocurrency theft and malware campaigns, overlapping with Sapphire Sleet.
CryptoCore is a North Korean threat actor focused on cryptocurrency theft, also known as BlueNoroff and Sapphire Sleet.
Two npm packages in the @joyfill namespace, @joyfill/layouts@0.1.2-2773.beta.0 and @joyfill/components@4.0.0-rc24-2773-beta.4, have been compromised to deliver a remote access trojan (RAT) associated with…
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate…
ClickFake Interview is a threat cluster tracked by Sekoia, associated with North Korea-aligned actors. It uses ClickFix-like lures to deceive targets into…