Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages designed to deploy a Python-based information stealer on…
Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages designed to deploy a Python-based information stealer on…
North Korean threat actors have been linked to the NullReceiver campaign, which uses trojanized npm packages to deploy malware that decodes C2…
Cybersecurity researchers have uncovered two malicious campaigns linked to North Korean threat actors, exploiting developer tools like Microsoft Visual Studio Code (VS…
A long-running North Korean cyber campaign that typically uses fake job offers and coding tests to lure victims. This iteration uses malvertising…
Lazarus Group is a North Korea-linked advanced persistent threat group known for cyber espionage and financially motivated attacks. It exploited CVE-2026-68820 as…
BlueNoroff is a North Korean cybercrime group targeting cryptocurrency exchanges and financial institutions, overlapping with Sapphire Sleet and UNC1069.
Cabbage RAT, also known as CageyChameleon, is a PowerShell-based remote access trojan used by North Korean threat actors for credential and data…
ScarCruft, also known as APT37, is a North Korean state-sponsored hacking group known for spear-phishing campaigns and deploying malware like RokRAT and…
APT37, also known as ScarCruft, is a North Korean cyber espionage group that has been active since at least 2012. They are…
The North Korean state-sponsored hacking group ScarCruft (APT37) has been observed using spear-phishing emails impersonating Microsoft Account security notifications to deliver a…