Contagious Interview Campaign
A long-running North Korean cyber campaign that typically uses fake job offers and coding tests to lure victims. This iteration uses malvertising…
A long-running North Korean cyber campaign that typically uses fake job offers and coding tests to lure victims. This iteration uses malvertising…
Lazarus Group is a North Korean state-sponsored cyber threat actor linked to numerous cyber espionage and financial theft operations. In this investigation,…
BlueNoroff is a North Korean cybercrime group targeting cryptocurrency exchanges and financial institutions, overlapping with Sapphire Sleet and UNC1069.
Cabbage RAT, also known as CageyChameleon, is a PowerShell-based remote access trojan used by North Korean threat actors for credential and data…
ScarCruft, also known as APT37, is a North Korean state-sponsored hacking group known for spear-phishing campaigns and deploying malware like RokRAT and…
APT37, also known as ScarCruft, is a North Korean cyber espionage group that has been active since at least 2012. They are…
The North Korean state-sponsored hacking group ScarCruft (APT37) has been observed using spear-phishing emails impersonating Microsoft Account security notifications to deliver a…
On June 17, 2026, a software supply chain attack codenamed 'easy-day-js' compromised 145 npm packages under the @mastra/* namespace, a popular open-source…
Sapphire Sleet is a North Korean cyber threat group also tracked as UNC1069, STARDUST CHOLLIMA, BlueNoroff, Alluring Pisces, CageyChameleon, and CryptoCore. It…
UNC1069 is a threat group attributed to North Korea, associated with the WAVESHAPER.V2 backdoor and activities overlapping with Sapphire Sleet. It has…