Tag: Democratic People’s Republic of Korea (DPRK)

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea
News

DPRK-Linked Hackers Use GitHub as C2 in Multi-Stage Attacks Targeting South Korea

GitHub has been seen to be used as command-and-control (C2) infrastructure by threat actors most likely connected to the Democratic People's Republic of Korea (DPRK) in multi-stage operations against South Korean companies. According to Fortinet FortiGuard Labs, the attack chain consists of obfuscated Windows shortcut (LNK) files that serve as the beginning point for dropping a PowerShell script that prepares the assault's subsequent phase and a decoy PDF document. It has been determined that phishing emails are used to disseminate these LNK files. The malicious PowerShell script runs quietly in the background while the victim is shown the PDF document as soon as the payloads are downloaded. The PowerShell script scans for active processes associated with virtual machines, debuggers...
$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation
News

$285 Million Drift Hack Traced to Six-Month DPRK Social Engineering Operation

According to Drift, the Democratic People's Republic of Korea (DPRK) carried out a months-long, carefully planned social engineering operation that started in the fall of 2025 and culminated in the April 1, 2026, attack that resulted in the theft of $285 million. A North Korean state-sponsored hacking group known as UNC4736, which is also monitored under the cyptonyms AppleJeus, Citrine Sleet, Golden Chollima, and Gleaming Pisces, was identified by the Solana-based decentralized exchange as "an attack six months in the making," with medium confidence. Since at least 2018, the threat actor has targeted the cryptocurrency industry for financial theft. The X_TRADER/3CX supply chain breach in 2023 and the $53 million theft of Radiant Capital, a decentralized finance (DeFi) platform, in ...
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs
News

OFAC Sanctions DPRK IT Worker Network Funding WMD Programs Through Fake Remote Jobs

Six people and two organizations have been sanctioned by the U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) for their participation in the Democratic People's Republic of Korea (DPRK) information technology (IT) worker scheme, which aims to defraud American companies and provide the regime with illegal funds to finance its WMD programs. According to Secretary of the Treasury Scott Bessent, the North Korean state targets American enterprises through dishonest schemes run by its offshore IT workers, who weaponize private information and demand large sums of money. The fraudulent operation, also known as Coral Sleet/Jasper Sleet, PurpleDelta, and Wagemole, helps the IT workers conceal their true origins and gain positions at reputable organizations in the Uni...
Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware
News

Lazarus Group Spotted Targeting Nuclear Engineers with CookiePlus Malware

In January 2024, the notorious threat actor Lazarus Group, associated with the Democratic People's Republic of Korea (DPRK), was seen using a "complex infection chain" to attack at least two employees of an unidentified nuclear-related company in a single month. The attacks, which resulted in the installation of a new modular backdoor called CookiePlus, are a component of Operation Dream Job, a lengthy cyber espionage effort that antivirus firm Kaspersky also tracks as NukeSped. Since at least 2020, when ClearSky made it public, it has been known to be operational. Targeting developers and workers in a variety of industries, such as defense, aerospace, cryptocurrency, and other international areas, with attractive employment possibilities that eventually lead to read more about Laza...
North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs
News

North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs

As part of a larger strategy to exploit information technology (IT) workers, threat actors with connections to the Democratic People's Republic of Korea (DPRK) are posing as software and technology consultancy companies based in the United States to achieve their financial goals. "Front companies, often based in China, Russia, Southeast Asia, and Africa, play a key role in masking the workers' true origins and managing payments," two security experts from SentinelOne, Tom Hegel and Dakota Cary, told The Hacker News in a study. The network of IT professionals in North Korea, both individually and through front firms, is said to be a means of generating illegal income and avoiding international sanctions placed on the regime read more about North Korean Front Companies Impersonate U.S...
North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS
News

North Korean Hackers Target Crypto Firms with Hidden Risk Malware on macOS

A threat actor with connections to the Democratic People's Republic of Korea (DPRK) has been seen using a multi-stage malware that can infect Apple macOS systems to target cryptocurrency-related enterprises. SentinelOne, a cybersecurity firm that named the campaign Hidden Risk, confidently attributed it to BlueNoroff, which has been connected to malware families like RustBucket, KANDYKORN, ObjCShellz, RustDoor (also known as Thiefbucket), and TodoSwift in the past. In a post shared with The Hacker News, researchers Raffaele Sabato, Phil Stokes, and Tom Hegel said that the activity infects targets with a malicious application masquerading as a PDF file by using emails that spread false information regarding bitcoin development read more about North Korean Hackers Target Crypto Firms...