Skip to main content
← All Articles

Tag

#DPRK

13 articles

Advertisement

North Korean Job Fraud Expands Beyond IT: New Sectors Targeted
MEDIUM
Threat Intel

North Korean Job Fraud Expands Beyond IT: New Sectors Targeted

DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.

Runtime Rebel Intel
5 min read · Sep 1, 2026
HIGH
Supply Chain

Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware

Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.

Runtime Rebel Intel
4 min read · Aug 21, 2026
DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft
HIGH
Threat Intel

DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft

North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.

Runtime Rebel Intel
3 min read · Jul 30, 2026
AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus
HIGH
Supply Chain

AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus

North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.

Runtime Rebel Intel
4 min read · Apr 29, 2026
Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks
HIGH
Threat Intel

Lazarus Group's $2B+ Crypto Theft: Defending Against Supply Chain Attacks

An analysis of Lazarus Group's persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.

Runtime Rebel Intel
5 min read · Apr 28, 2026
DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories
HIGH
Threat Intel

DPRK's 'Contagious Interview' Spreads RATs via Dev Repositories

DPRK threat actors are employing a 'contagious interview' scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…

Runtime Rebel Intel
5 min read · Apr 22, 2026

Advertisement

HIGH
Threat Intel

DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud

Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.

Runtime Rebel Intel
4 min read · Apr 16, 2026
DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea
MEDIUM
Threat Intel

DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea

North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.

Runtime Rebel Intel
4 min read · Apr 6, 2026
DPRK Social Engineering Behind $285 Million Drift Hack: Analysis
HIGH
Threat Intel

DPRK Social Engineering Behind $285 Million Drift Hack: Analysis

A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.

Runtime Rebel Intel
3 min read · Apr 5, 2026
HIGH
Supply Chain

TeamPCP Supply Chain: CERT-EU Confirms Cloud Breach, 1000+ SaaS Environments Affected

CERT-EU confirms European Commission cloud breach via TeamPCP supply chain campaign. Mandiant identifies over 1,000 compromised SaaS environments.

Runtime Rebel Intel
5 min read · Apr 3, 2026
Drift Protocol Hacked for $285M via Durable Nonce Attack
HIGH
Data Breach

Drift Protocol Hacked for $285M via Durable Nonce Attack

Solana-based DEX Drift Protocol lost $285 million due to a social engineering and durable nonce attack, leading to Security Council takeover.

Runtime Rebel Intel
4 min read · Apr 3, 2026
OFAC Sanctions DPRK IT Worker Network Funding WMD Programs
MEDIUM
Threat Intel

OFAC Sanctions DPRK IT Worker Network Funding WMD Programs

US Treasury sanctions North Korea's IT worker network used to fund WMD programs. Learn how these actors use fake identities and how to secure remote hiring.

Runtime Rebel Intel
4 min read · Mar 18, 2026
HIGH
Identity & Access

Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure

Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.

Runtime Rebel Intel
2 min read · Feb 23, 2026