Tag: North Korea

North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations
News

North Korea-Linked UNC1069 Uses AI Lures to Attack Cryptocurrency Organizations

UNC1069, a threat actor with ties to North Korea, has been seen targeting the cryptocurrency industry in an attempt to obtain private information from Windows and macOS devices in order to facilitate financial theft. According to Google Mandiant experts Ross Inman and Adrian Hernandez, the breach used a social engineering approach that included a hacked Telegram account, a phony Zoom meeting, a ClickFix infection vector, and reported use of AI-generated video to trick the victim. UNC1069, which has been active since at least April 2018, has a history of using phony meeting invites and impersonating investors from respectable companies on Telegram to carry out social engineering efforts for financial benefit. The larger cybersecurity community also keeps tabs on it under the names MA...
North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft
News

North Korea-Linked Hackers Steal $2.02 Billion in 2025, Leading Global Crypto Theft

At least $2.02 billion of the more than $3.4 billion stolen between January and early December in 2025 came from threat actors with connections to the Democratic People's Republic of Korea (DPRK or North Korea). According to Chainalysis' Crypto Crime Report, which was released with The Hacker News, the amount reflects a 51% growth year over year and $681 million more than in 2024, when the threat actors took $1.3 billion. According to the blockchain intelligence firm, DPRK attacks accounted for a record 76% of all service compromises, making this the worst year on record for DPRK crypto theft in terms of value stolen. Of the $2.02 billion that North Korea stole, $1.5 billion came from the February hack of the cryptocurrency exchange Bybit alone. A threat cluster called TraderTrai...
North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware
News

North Korea-linked Actors Exploit React2Shell to Deploy New EtherRAT Malware

Threat actors with connections to North Korea are probably the most current to use the recently revealed major security React2Shell vulnerability in React Server Components (RSC) to distribute an unreported remote access trojan known as EtherRAT. In a research released on Monday, Sysdig stated that EtherRAT uses five separate Linux persistence techniques, downloads its own Node.js runtime from nodejs.org, and uses Ethereum smart contracts for command-and-control (C2) resolution. According to the cloud security company, there is a substantial overlap between the activity and a long-running campaign known as Contagious Interview, which has been using the EtherHiding approach to spread malware since February 2025. The term "Contagious Interview" refers to a set of attacks that targe...
Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera
News

Researchers Capture Lazarus APT’s Remote-Worker Scheme Live on Camera

One of North Korea's most persistent infiltration schemes—a network of remote IT workers connected to Lazarus Group's renowned Chollima division—was discovered through a joint investigation headed by Mauro Eldritch, founder of BCA LTD, in collaboration with threat-intel initiative NorthScan and ANY.RUN, a solution for interactive malware analysis and threat intelligence. Researchers were able to observe the operators in action for the first time, recording their work on what they thought were actual development computers. On the other hand, the machines were long-running, highly controlled sandbox environments built by ANY.RUN. The operation began when NorthScan's Heiner García impersonated a U.S. developer targeted by a Lazarus recruiter using the alias "Aaron" (also known as "Blaz...
U.S. Seizes $7.74M in Crypto Tied to North Korea’s Global Fake IT Worker Network
News

U.S. Seizes $7.74M in Crypto Tied to North Korea’s Global Fake IT Worker Network

A civil forfeiture case targeting approximately $7.74 million in cryptocurrencies, non-fungible tokens (NFTs), and other digital assets purportedly connected to a global IT worker scheme hatched by North Korea has been filed in federal court, according to the U.S. Department of Justice (DoJ). According to Sue J. Bai, Head of the Justice Department's National Security Division, North Korea has been using cryptocurrency ecosystems and international remote IT contracting for years to circumvent U.S. sanctions and finance its weapons development. According to the Justice Department, the money were initially blocked in relation to an indictment filed in April 2023 against Sim Hyon-Sop, a representative of the North Korean Foreign Trade Bank (FTB), who is suspected of plotting with the IT...
North Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks
News

North Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks

Two new malware variants, KLogEXE and FPSpy, have been used by threat actors connected to North Korea. An enemy identified as Kimsuky—also known as APT43, ARCHIPELAGO, Black Banshee, Emerald Sleet (formerly Thallium), Sparkling Pisces, Velvet Chollima, and Springtail—has been linked to the activities. Researchers Daniel Frank and Lior Rochberger from Palo Alto Networks Unit 42 noted that these samples show off Sparkling Pisces' ever-expanding armament and its ongoing evolution. The threat actor, who has been active since at least 2012, has earned the moniker "king of spear phishing" for his skill at tricking people into downloading malware by pretending to be trusted sources in emails read more about North Korean Hackers Deploy New KLogEXE and FPSpy Malware in Targeted Attacks. ...
FBI warns crypto firms of aggressive social engineering attacks
News

FBI warns crypto firms of aggressive social engineering attacks

The FBI issued a warning today about North Korean hacker gangs that are actively pursuing cryptocurrency businesses and their staff members using cunning social engineering techniques to spread malware intended to steal their bitcoin holdings. The FBI claims that its social engineering techniques are extremely focused and challenging to identify, especially for individuals possessing sophisticated cybersecurity knowledge. Threat actors from North Korea have been seen extensively researching possible targets over the past several months, with a particular focus on people associated with bitcoin exchange-traded funds (ETFs) and other similar financial instruments. Pre-operational staging at this stage implies that they are getting ready for possible attacks on businesses linked to...
University Professors Targeted by North Korean Cyber Espionage Group
News

University Professors Targeted by North Korean Cyber Espionage Group

Kimsuky, a threat actor associated with North Korea, has been connected to a fresh series of cyberattacks aimed at academics, researchers, and university employees in an attempt to obtain intelligence. The behavior was discovered in late July 2024, according to cybersecurity company Resilience, when it noticed an operation security (OPSEC) error committed by the hackers. Kimsuky is just one of many offensive cyber teams led by the North Korean military and administration. Other names for Kimsuky include APT43, ARCHIPELAGO, Black Banshee, Emerald Sleet, Springtail, and Velvet Chollima. Moreover, it is highly active, frequently using spear-phishing tactics as a springboard to offer an ever-expanding array of specialized tools for reconnaissance, data theft, and establishing permane...
North Korea’s Lazarus Group Deploys New Kaolin RAT via Fake Job Lures
News

North Korea’s Lazarus Group Deploys New Kaolin RAT via Fake Job Lures

In summer 2023, the North Korea-affiliated threat actor Lazarus Group used its tried-and-true fake job lures to distribute a new remote access trojan named Kaolin RAT as part of attacks directed at certain targets in the Asia-Pacific area. In addition to performing typical remote access tasks (RATs), the malware has the ability to modify the file's last write timestamp and load any DLL binary that is received from a command-and-control server, according to a report released last week by Avast security researcher Luigino Camastra. The appid.sys driver's now-patched admin-to-kernel exploit (CVE-2024-21338, CVSS score: 7.8) allows the rootkit FudModule to be delivered via the RAT. Once inside, it can use this attack to get a kernel read/write primitive and eventually disable security p...
North Korea-linked Kimsuky Shifts to Compiled HTML Help Files in Ongoing Cyberattacks
News

North Korea-linked Kimsuky Shifts to Compiled HTML Help Files in Ongoing Cyberattacks

Kimsuky, also known as Black Banshee, Emerald Sleet, or Springtail, is a threat actor associated with North Korea that has been found to be changing its strategies. It now uses Compiled HTML Help (CHM) files as delivery vectors to distribute malware that harvests sensitive data. Kimsuky is known to target entities in South Korea, North America, Asia, and Europe. It has been active since at least 2012. Rapid7 claims that attack chains have used Windows shortcut (LNK) files, ISO files, and weaponized Microsoft Office documents. The group has also been known to use CHM files to spread malware on infected computers. Based on comparable tradecraft seen in the past, the cybersecurity firm has moderately confidently ascribed the behavior to Kimsuky read more North Korea linked Kimsuky S...