Tag: North Korean

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels
News

North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels

Two malicious cyber campaigns that resemble the ongoing North Korean threat cluster known as Contagious Interview (also known as Famous Chollima, HexagonalRodent, and Void Dokkaebi) have been identified by cybersecurity researchers. The threat actor has been discovered planning phishing attacks that use themes related to code reviews or developer role recruitment to target almost 100 companies in a variety of industries, including technology, education, banking, and cryptocurrencies, according to a research released by Proofpoint. The code for the action is UNK_DeadDrop. According to Proofpoint researchers Saher Naumaan and Carlos Rubio, the infection chain starts with emails that contain links to actor-controlled GitHub repositories hosting malicious scripts that cause cross-platfo...
FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing
News

FBI Warns North Korean Hackers Using Malicious QR Codes in Spear-Phishing

On Thursday, the U.S. Federal Bureau of Investigation (FBI) issued a warning about North Korean state-sponsored threat actors using malicious QR codes in spear-phishing efforts that target North Korean enterprises. According to the FBI's flash notice, as of 2025, Kimsuky actors have used spear-phishing campaigns with malicious Quick Response (QR) codes to target think tanks, academic institutions, and both foreign and U.S. government bodies. Quishing is the term for this kind of spear-phishing assault. By forcing victims to switch from a machine protected by business policies to a mobile device that might not provide the same level of protection, the usage of QR codes for phishing successfully allows threat actors to get around conventional protections. Threat group Kimsuky, also...
OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks
News

OpenAI Disrupts Russian, North Korean, and Chinese Hackers Misusing ChatGPT for Cyberattacks

Three activity clusters were terminated by OpenAI on Tuesday for abusing its ChatGPT artificial intelligence (AI) tool to aid in the creation of malware. Among them is a Russian-speaking threat actor who allegedly utilized the chatbot to assist in the creation and improvement of a remote access trojan (RAT), a credential stealer designed to avoid detection. Additionally, the operator prototyped and debugged technical elements that facilitate credential theft and post-exploitation using multiple ChatGPT accounts. We saw that these accounts posted proof of their activity in a Telegram channel devoted to Russian-speaking criminal gangs, suggesting that these accounts are associated with those actors, according to OpenAI. Although the threat actor's direct requests for malicious cont...
North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware
News

North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware

An continuing effort targets freelance software developers with cross-platform malware families called BeaverTail and InvisibleFerret, using lures with a job interview theme. Codenamed DeceptiveDevelopment, the activity has been associated with North Korea and overlaps with clusters monitored under the names DEV#POPPER, Famous Chollima, PurpleBravo, Tenacious Pungsan, and Contagious Interview (also known as CL-STA-0240). The campaign began in late 2023 at the latest. According to a research published with The Hacker News, cybersecurity firm ESET claims that DeceptiveDevelopment uses spear-phishing on job-hunting and freelance websites to target independent software developers with the goal of stealing read more about North Korean Hackers Target Freelance Developers in Job Scam to De...
North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks
News

North Korean APT43 Uses PowerShell and Dropbox in Targeted South Korea Cyberattacks

An continuing effort targeting South Korean government, business, and cryptocurrency sectors has been traced to a nation-state threat actor with ties to North Korea. The hacking collective known as Kimsuky, which is also known by the names APT43, Black Banshee, Emerald Sleet, Sparkling Pisces, Springtail, TA427, and Velvet Chollima, has been implicated in the attack campaign, which Securonix has named DEEP#DRIVE. In a report shared with The Hacker News, security researchers Den Iuzvyk and Tim Peck described the activity as a "sophisticated and multi-stage operation," stating that the attackers successfully infiltrated targeted environments by using customized phishing lures written in Korean and masquerading as authentic documents read more about North Korean APT43 Uses PowerShell a...
DoJ Indicts 5 Individuals for $866K North Korean IT Worker Scheme Violations
News

DoJ Indicts 5 Individuals for $866K North Korean IT Worker Scheme Violations

In violation of international sanctions, the U.S. Department of Justice (DoJ) indicted two North Korean nationals, a Mexican national, and two of its own citizens on Thursday for allegedly participating in the ongoing fraudulent information technology (IT) worker scheme that aims to make money for the DPRK. Emanuel Ashtor, Pedro Ernesto Alonso De Los Reyes, Erick Ntekereze Prince, Pak Jin-Song (박진성), and Jin Sung-Il (진성일) are the targets of the action. On January 10, 2025, Alonso, who lives in Sweden, was taken into custody in the Netherlands following the issuance of a warrant. Conspiracy to destroy a protected computer, conspiracy to commit mail and wire fraud, conspiracy to launder money, and conspiracy to transfer are the charges against all five defendants read more about DoJ I...
North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains
News

North Korean IT Worker Fraud Linked to 2016 Crowdfunding Scam and Fake Domains

Researchers studying cybersecurity have discovered infrastructural connections between a 2016 crowdfunding scam and the North Korean threat actors responsible for the fake IT worker schemes. According to a report sent to The Hacker News, the fresh information raises the possibility that threamoret groups based in Pyongyang may have carried out illegal money-making schemes before using IT professionals. In order to provide income for the sanctioned country, North Korean actors secretly seek employment under false identities in order to infiltrate businesses in the West and other parts of the world as part of the IT worker fraud scam, which was discovered in late 2023. The names Famous Chollima, Nickel Tapestry, UNC5267, and Wagemole are also used to track it read more about North Kor...
North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn
News

North Korean Hackers Steal $10M with AI-Driven Scams and Malware on LinkedIn

According to estimates, Sapphire Sleet, a threat actor with ties to North Korea, stole over $10 million worth of cryptocurrencies over the course of six months of social engineering activities. According to Microsoft's research, many threat activity clusters with connections to the nation have been seen fabricating LinkedIn profiles that pretend to be both recruiters and job seekers in order to raise illegal funds for the sanctioned country. Hacking organizations APT38 and BlueNoroff overlap with Sapphire Sleet, which has been active since at least 2020. The tech firm disclosed in November 2023 that the threat actor had set up infrastructure to conduct its social engineering efforts by mimicking skills evaluation platforms read more North Korean Hackers Steal $10M with AI-Driven Sca...
North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs
News

North Korean Front Companies Impersonate U.S. IT Firms to Fund Missile Programs

As part of a larger strategy to exploit information technology (IT) workers, threat actors with connections to the Democratic People's Republic of Korea (DPRK) are posing as software and technology consultancy companies based in the United States to achieve their financial goals. "Front companies, often based in China, Russia, Southeast Asia, and Africa, play a key role in masking the workers' true origins and managing payments," two security experts from SentinelOne, Tom Hegel and Dakota Cary, told The Hacker News in a study. The network of IT professionals in North Korea, both individually and through front firms, is said to be a means of generating illegal income and avoiding international sanctions placed on the regime read more about North Korean Front Companies Impersonate U.S...
North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data
News

North Korean IT Workers in Western Firms Now Demanding Ransom for Stolen Data

In addition to stealing intellectual property, North Korean IT workers who pose as foreign employees and work for Western corporations are also demanding ransoms to keep their stolen material secret, adding a new dimension to their financially driven attacks. Secureworks Counter Threat Unit (CTU) revealed in a research released this week that in certain cases, fraudulent personnel demanded ransom payments from their former employers after getting insider access—a practice not seen in previous scams. In one instance, a contractor began working in mid-2024 and almost immediately began exfiltrating proprietary data. The cybersecurity organization noted that Nickel Tapestry, also known as Famous Chollima and UNC5267, is a threat group it tracks, and this action is comparable to them rea...