At a glance Actor DPRK-linked group (Sapphire Sleet, Stardust Chollima, BlueNoroff, UNC1069) Activity NPM supply chain compromise...
North Korea
At a glance Threat actor Famous Chollima, also called Wagemole; North Korea-aligned Activity type Social engineering via...
At a glance Actor or group Kimsuky, a North Korea-linked group also tracked as Springtail, Thallium and...
At a glance Actor / group DPRK-aligned group behind the Contagious Interview campaign (Elastic tracks it as...
At a glance Malware family RokRAT variant (x64) Threat actor Assessed highly likely APT37 (suspected, not confirmed)...
At a glance Actor Suspected North Korean Lazarus-linked group (attribution by TTP similarity) Activity npm supply chain...
In the ever-evolving landscape of cyber warfare, software developers have become prime targets for state-sponsored threat actors....
The corporate perimeter has been breached, and the threat isn’t coming through an external firewall—it’s sitting on...
Cybersecurity researchers at Panther Threat Research have released a detailed exposé on a massive, coordinated npm malware...
In a sophisticated shift away from traditional software exploitation, the North Korean state-sponsored threat actor Sapphire Sleet...
In a sophisticated escalation of cyber-enabled financial theft, security researchers from Validin have unmasked a sprawling campaign...
In what federal prosecutors are calling a sophisticated strike against national security, two New Jersey residents have...
Security researchers from the OpenSourceMalware (OSM) team have uncovered a massive and rapidly expanding threat campaign targeting...
A new investigative report from Panther has identified a dangerous cluster of malicious packages lurking within the...
The ReversingLabs (RL) research team has uncovered a sophisticated expansion of the “graphalgo” campaign. Originally identified in...
North Korea’s cyber program has moved past the era of accidental growth into a period of “mature...
In a calculated move that signals a new frontier in cyber espionage, North Korean threat actors have...
On April 1, 2026, the decentralized finance (DeFi) world was rocked as attackers drained approximately USD 285...
Researchers at Socket have identified a massive new cluster of malicious packages linked to North Korea’s notorious...
In a sophisticated blend of social engineering and decentralized technology, eSentire’s Threat Response Unit (TRU) recently detected...
The Google Threat Intelligence Group (GTIG) has issued an urgent warning regarding a sophisticated software supply chain...
In an attempt to infiltrate the cybersecurity industry itself, a suspected North Korean (DPRK) IT worker recently...