<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #DPRK</title><description>Cybersecurity articles tagged #DPRK on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>North Korean Job Fraud Expands Beyond IT: New Sectors Targeted</title><link>https://runtimerebel.com/blog/north-korean-job-fraud-expands-beyond-it-new-sectors-targeted</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-job-fraud-expands-beyond-it-new-sectors-targeted</guid><description>DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.</description><pubDate>Tue, 01 Sep 2026 02:38:21 GMT</pubDate><category>DPRK</category><category>North Korea</category><category>Insider Threat</category><category>AI</category><category>Job Fraud</category></item><item><title>Critical: Rust `arrayref` Crate Poisoned with Infostealer Malware</title><link>https://runtimerebel.com/blog/critical-rust-arrayref-crate-poisoned-with-infostealer-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/critical-rust-arrayref-crate-poisoned-with-infostealer-malware</guid><description>Hackers compromised `arrayref`, `append-only-vec`, and `internment` Rust crates to inject infostealer malware, impacting developers and downstream projects.</description><pubDate>Fri, 21 Aug 2026 00:43:46 GMT</pubDate><category>Rust</category><category>Supply Chain Attack</category><category>Infostealer</category><category>DPRK</category><category>Crates Io</category></item><item><title>DPRK-Linked macOS Malvertising Uses Fake Updates for Crypto Theft</title><link>https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-linked-macos-malvertising-uses-fake-updates-for-crypto-theft</guid><description>North Korean threat actors are using deceptive full-screen macOS update pages to distribute crypto-stealing malware in a new Contagious Interview campaign.</description><pubDate>Thu, 30 Jul 2026 21:11:51 GMT</pubDate><category>macOS</category><category>Lazarus Group</category><category>Malvertising</category><category>Cryptocurrency</category><category>DPRK</category></item><item><title>AI-Generated npm Supply Chain Attack: DPRK Exploits Claude Opus</title><link>https://runtimerebel.com/blog/ai-generated-npm-supply-chain-attack-dprk-exploits-claude-opus</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-generated-npm-supply-chain-attack-dprk-exploits-claude-opus</guid><description>North Korean actors leverage LLMs like Claude Opus to insert malicious npm packages into developer workflows, leading to RCE and data theft via @validate-sdk/v2.</description><pubDate>Wed, 29 Apr 2026 16:38:11 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>NPM</category><category>Malware</category><category>Claude Opus</category></item><item><title>Lazarus Group&apos;s $2B+ Crypto Theft: Defending Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-s-2b-crypto-theft-defending-against-supply-chain-attacks</guid><description>An analysis of Lazarus Group&apos;s persistent and financially motivated cyber operations, highlighting over $2B in crypto theft and critical supply chain attack risks.</description><pubDate>Tue, 28 Apr 2026 16:47:53 GMT</pubDate><category>Lazarus Group</category><category>DPRK</category><category>Cryptocurrency Theft</category><category>Supply Chain Attack</category><category>Financial Cybercrime</category><category>APT</category></item><item><title>DPRK&apos;s &apos;Contagious Interview&apos; Spreads RATs via Dev Repositories</title><link>https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-s-contagious-interview-spreads-rats-via-dev-repositories</guid><description>DPRK threat actors are employing a &apos;contagious interview&apos; scam, weaponizing compromised developer repositories to propagate RATs and malware across the software supply…</description><pubDate>Wed, 22 Apr 2026 20:27:05 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>Fake Job Scam</category><category>RAT</category><category>Software Supply Chain</category><category>Social Engineering</category><category>Developer Compromise</category></item><item><title>DPRK IT Worker Laptop Farms: U.S. Nationals Sentenced for Fraud</title><link>https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-it-worker-laptop-farms-u-s-nationals-sentenced-for-fraud</guid><description>Two U.S. residents sentenced for operating laptop farms that enabled North Korean IT workers to defraud Fortune 500 companies using stolen identities.</description><pubDate>Thu, 16 Apr 2026 08:40:47 GMT</pubDate><category>DPRK</category><category>Laptop Farm</category><category>Insider Threat</category><category>Identity Theft</category><category>Lazarus Group</category></item><item><title>DPRK Hackers Abuse GitHub Infrastructure for C2 in South Korea</title><link>https://runtimerebel.com/blog/dprk-hackers-abuse-github-infrastructure-for-c2-in-south-korea</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-hackers-abuse-github-infrastructure-for-c2-in-south-korea</guid><description>North Korean state-sponsored actors are leveraging GitHub as a command-and-control platform in complex multi-stage attacks targeting South Korean organizations.</description><pubDate>Mon, 06 Apr 2026 20:17:41 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>GitHub C2</category><category>South Korea</category><category>LNK</category><category>PowerShell</category></item><item><title>DPRK Social Engineering Behind $285 Million Drift Hack: Analysis</title><link>https://runtimerebel.com/blog/dprk-social-engineering-behind-285-million-drift-hack-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/dprk-social-engineering-behind-285-million-drift-hack-analysis</guid><description>A deep dive into the six-month DPRK social engineering operation targeting Drift protocol, resulting in a $285 million Solana-based cryptocurrency theft.</description><pubDate>Sun, 05 Apr 2026 20:11:07 GMT</pubDate><category>DPRK</category><category>Lazarus Group</category><category>Drift Protocol</category><category>Social Engineering</category><category>Solana</category><category>Cryptocurrency Theft</category></item><item><title>TeamPCP Supply Chain: CERT-EU Confirms Cloud Breach, 1000+ SaaS Environments Affected</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-cert-eu-confirms-cloud-breach-1000-saas-environments-affected</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-cert-eu-confirms-cloud-breach-1000-saas-environments-affected</guid><description>CERT-EU confirms European Commission cloud breach via TeamPCP supply chain campaign. Mandiant identifies over 1,000 compromised SaaS environments.</description><pubDate>Fri, 03 Apr 2026 16:19:26 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Cloud Security</category><category>SaaS</category><category>European Commission</category><category>DPRK</category></item><item><title>Drift Protocol Hacked for $285M via Durable Nonce Attack</title><link>https://runtimerebel.com/blog/drift-protocol-hacked-for-285m-via-durable-nonce-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/drift-protocol-hacked-for-285m-via-durable-nonce-attack</guid><description>Solana-based DEX Drift Protocol lost $285 million due to a social engineering and durable nonce attack, leading to Security Council takeover.</description><pubDate>Fri, 03 Apr 2026 12:21:37 GMT</pubDate><category>Drift Protocol</category><category>Solana</category><category>Durable Nonce</category><category>Social Engineering</category><category>DPRK</category><category>Cryptocurrency</category><category>DeFi</category></item><item><title>OFAC Sanctions DPRK IT Worker Network Funding WMD Programs</title><link>https://runtimerebel.com/blog/ofac-sanctions-dprk-it-worker-network-funding-wmd-programs</link><guid isPermaLink="true">https://runtimerebel.com/blog/ofac-sanctions-dprk-it-worker-network-funding-wmd-programs</guid><description>US Treasury sanctions North Korea&apos;s IT worker network used to fund WMD programs. Learn how these actors use fake identities and how to secure remote hiring.</description><pubDate>Wed, 18 Mar 2026 20:15:49 GMT</pubDate><category>DPRK</category><category>OFAC</category><category>Lazarus Group</category><category>Sanctions</category><category>IT Worker Scheme</category></item><item><title>Sentenced: Ukrainian National Facilitated DPRK IT Worker Infrastructure</title><link>https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/sentenced-ukrainian-national-facilitated-dprk-it-worker-infrastructure</guid><description>Oleksandr Didenko sentenced to five years for orchestrating an identity laundering scheme that enabled North Korean operatives to infiltrate Western corporate networks.</description><pubDate>Mon, 23 Feb 2026 16:26:29 GMT</pubDate><category>DPRK</category><category>Identity Theft</category><category>Remote Work Fraud</category><category>Insider Threat</category><category>Lazarus Group</category></item></channel></rss>