⤷ Title: The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 06:30:05 +0000
════════════════════════
⌗ Tags: #Cybercriminals #2026 #Blockchain C2 #CI/CD #Cursor AI #developer security #DPRK #infosec #malware #North Korea #npm #Panther Threat Research #Polymarket #supply chain attack #WindSurf
Daily CyberSecurity
The Malware Factory: Unmasking the 108-Package North Korean Siege on npm
Panther Research exposes a massive 2026 DPRK npm campaign using blockchain dead-drops to steal crypto keys and AI secrets. Secure your CI/CD pipelines now.
⤷ Title: Two Strikes, Half a Billion: How North Korean Hackers Seized 76% of All Stolen Crypto in Just 120 Days
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 07:46:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bridge Exploit #Crypto Theft #Cybersecurity 2026 #DPRK #Drift Protocol #KelpDAO #LayerZero #Lazarus Group #North Korea #Solana #TraderTraitor #TRM Labs
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 05 May 2026 07:46:25 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Bridge Exploit #Crypto Theft #Cybersecurity 2026 #DPRK #Drift Protocol #KelpDAO #LayerZero #Lazarus Group #North Korea #Solana #TraderTraitor #TRM Labs
Penetration Testing Tools
Two Strikes, Half a Billion: How North Korean Hackers Seized 76% of All Stolen Crypto in Just 120 Days
North Korean cyber-operatives have once again demonstrated how a handful of precision strikes can fundamentally reshape annual cryptocurrency
⤷ Title: Rigged Game: How North Korea’s ScarCruft Group Infiltrated a Gaming Platform to Deploy BirdCall Spyware
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:54:33 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #APT37 #BirdCall #BirdCall Backdoor #Cybersecurity 2026 #ESET #North Korea #RoKRAT #ScarCruft #sqgame.net #supply chain attack #Windows Spyware #Yanbian
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:54:33 +0000
════════════════════════
⌗ Tags: #Malware #Android malware #APT37 #BirdCall #BirdCall Backdoor #Cybersecurity 2026 #ESET #North Korea #RoKRAT #ScarCruft #sqgame.net #supply chain attack #Windows Spyware #Yanbian
Penetration Testing Tools
Rigged Game: How North Korea’s ScarCruft Group Infiltrated a Gaming Platform to Deploy BirdCall Spyware
The seemingly innocuous download of a mobile game could culminate in a smartphone being compromised by sophisticated spyware.
⤷ Title: North Korean “Laptop Farms” Infiltrated 70 U.S. Companies
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 10:13:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #corporate espionage #cybersecurity #DPRK #Erick Prince #fbi #Insider Threat #Justice Department #Laptop Farm #Matthew Knoot #North Korea #Remote Desktop #Stolen Identity
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 08 May 2026 10:13:07 +0000
════════════════════════
⌗ Tags: #Cybercriminals #corporate espionage #cybersecurity #DPRK #Erick Prince #fbi #Insider Threat #Justice Department #Laptop Farm #Matthew Knoot #North Korea #Remote Desktop #Stolen Identity
Daily CyberSecurity
North Korean "Laptop Farms" Infiltrated 70 U.S. Companies
DOJ sentences U.S. enablers for running North Korean "laptop farms." Learn how the DPRK breached 70 companies and funded weapons via stolen identities.
⤷ Title: DeFi Hacks Are Getting Smarter And Your Crypto Portfolio Could Pay the Price
════════════════════════
𐀪 Author: F.uzoma
════════════════════════
ⴵ Time: Fri, 08 May 2026 11:46:45 GMT
════════════════════════
⌗ Tags: #defi #hacking #cryptocurrency_investment #cryptosecurity #north_korea
════════════════════════
𐀪 Author: F.uzoma
════════════════════════
ⴵ Time: Fri, 08 May 2026 11:46:45 GMT
════════════════════════
⌗ Tags: #defi #hacking #cryptocurrency_investment #cryptosecurity #north_korea
Medium
DeFi Hacks Are Getting Smarter And Your Crypto Portfolio Could Pay the Price
The numbers from April 2026 are hard to look away from. The month recorded a significant number of cryptocurrency hacking with total losses…
⤷ Title: Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:54:34 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Cybersecurity #Erick Prince #Fraud #Laptop Farms #Matthew Knoot #North Korea #Scam #USA
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Sun, 10 May 2026 19:54:34 +0000
════════════════════════
⌗ Tags: #Cyber Crime #Cybersecurity #Erick Prince #Fraud #Laptop Farms #Matthew Knoot #North Korea #Scam #USA
Hackread
Two US Men Jailed for Helping North Korean Hackers Infiltrate US Firms
Matthew Knoot and Erick Prince have been jailed for 18 months each for helping North Korean hackers infiltrate US firms through remote laptop farms.
⤷ Title: APT37’s New “Python-in-a-Cat” Malware Uses Environment Variable Obfuscation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 08:13:34 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Batch Script Obfuscation #Cyberespionage #Genians #infosec #LNK File #Malware Analysis #North Korea APT #phishing #Python Malware #threat intelligence
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 12 May 2026 08:13:34 +0000
════════════════════════
⌗ Tags: #Malware #APT37 #Batch Script Obfuscation #Cyberespionage #Genians #infosec #LNK File #Malware Analysis #North Korea APT #phishing #Python Malware #threat intelligence
Daily CyberSecurity
APT37’s New "Python-in-a-Cat" Malware Uses Environment Variable Obfuscation
Genians unmasks an APT37 campaign using environment variable tricks and compiled Python malware to bypass EDR. Protect your network from these stealthy lures.
⤷ Title: The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:09:38 +0000
════════════════════════
⌗ Tags: #Cybercriminals #crypto exfiltration networks #decentralized finance subversion #developer environment exploitation #fake remote employee scams #initial access methodologies #Krypt3ia threat intelligence #laptop farm infrastructure #North Korea cyber threats #supply chain interdiction #zero trust verification
Information Security News
The Consolidation of North Korean Cyber Doctrine: From Fragmented Threat Actors to a Unified Cyber Ecosystem
North Korea’s adversarial presence within the digital theater has transcended the legacy paradigm of isolated, decentralized hacking collectives. Per comprehensive threat intelligence compiled by …
⤷ Title: The Evolutionary Stratagem of Void Dokkaebi: Analyzing the Cythonized Mutation of InvisibleFerret
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:05:06 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail browser extension injection #code assessment social engineering #compiled pyd and so binaries #cryptocurrency wallet exfiltration #Famous Chollima developer target #InvisibleFerret Cython backdoor #Manifest V2 browser downgrade #North Korean APT defense #TrendAI threat research #Void Dokkaebi malware evasion
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 26 May 2026 07:05:06 +0000
════════════════════════
⌗ Tags: #Malware #BeaverTail browser extension injection #code assessment social engineering #compiled pyd and so binaries #cryptocurrency wallet exfiltration #Famous Chollima developer target #InvisibleFerret Cython backdoor #Manifest V2 browser downgrade #North Korean APT defense #TrendAI threat research #Void Dokkaebi malware evasion
Information Security News
Void Dokkaebi Malware Evasion: Cython Backend Defeats Detection
North Korea's Void Dokkaebi campaign uses Cython to compile the InvisibleFerret backdoor into binary files, successfully bypassing legacy Python security rules.
⤷ Title: UNK_DeadDrop: North Korean Hackers Target Developers
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 03:52:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cryptocurrency Theft #Cursor IDE #cybersecurity #Developer Phishing #GitHub malware #North Korean Hackers #UNK_DeadDrop
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 03:52:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Cryptocurrency Theft #Cursor IDE #cybersecurity #Developer Phishing #GitHub malware #North Korean Hackers #UNK_DeadDrop
Information Security News
UNK_DeadDrop: North Korean Hackers Target Developers
North Korean hackers run the UNK_DeadDrop campaign, using fake job offers and GitHub repos to plant malware and steal crypto from developers.