PROBABLYPWNED
Home/Tag/North Korea

North Korea

22 articles tagged with "North Korea"

APT37 Exploits Facebook Friendships to Deploy RokRAT
Threat Intelligence4 min read

APT37 Exploits Facebook Friendships to Deploy RokRAT

North Korean threat actors are befriending targets on Facebook, building trust over weeks, then delivering RokRAT malware through trojanized PDF readers. Military and government officials targeted.

Alex KowalskiApr 29, 2026
Omnistealer: North Korean Malware Hides C2 in Blockchain
Malware4 min read

Omnistealer: North Korean Malware Hides C2 in Blockchain

eSentire researchers expose Omnistealer, a North Korean infostealer storing payloads in blockchain transactions. 300,000 credentials compromised across government and defense sectors.

James RiveraApr 15, 2026
North Korea Behind $285M Drift Protocol Heist
Data Breaches3 min read

North Korea Behind $285M Drift Protocol Heist

Solana's Drift Protocol lost $285 million in 2026's largest DeFi hack. TRM Labs attributes the attack to North Korean actors who exploited oracle manipulation and pre-signed transactions.

Sarah MitchellApr 4, 2026
North Korea Uses GitHub as C2 in South Korea Attacks
Threat Intelligence4 min read

North Korea Uses GitHub as C2 in South Korea Attacks

FortiGuard Labs exposes DPRK campaign using LNK files and GitHub repositories for command-and-control against South Korean targets. 22 evasion techniques identified.

Alex KowalskiApr 3, 2026
APT37 Ruby Jumper Campaign Targets Air-Gapped Networks
Threat Intelligence4 min read

APT37 Ruby Jumper Campaign Targets Air-Gapped Networks

North Korean APT37 deploys six new malware tools to breach air-gapped systems using USB drives and cloud C2. Zscaler reveals RESTLEAF, THUMBSBD, and FOOTWINE surveillance capabilities.

Alex KowalskiFeb 27, 2026
North Korea Uses Deepfake Zoom Calls in Crypto Heists
Threat Intelligence4 min read

North Korea Uses Deepfake Zoom Calls in Crypto Heists

Google Mandiant exposes UNC1069's use of AI-generated deepfake video, compromised executive accounts, and ClickFix attacks to deploy macOS malware against cryptocurrency firms.

Alex KowalskiFeb 12, 2026
North Korea's Cyber Army: A Lazarus Group Profile
Threat Intelligence5 min read

North Korea's Cyber Army: A Lazarus Group Profile

DPRK hackers stole $2B in cryptocurrency in 2025 alone. Understanding Lazarus Group's operations helps defend against state-sponsored financial theft.

Alex KowalskiJan 10, 2026