Skip to main content
← All Articles

Tag

#North Korea

26 articles

Advertisement

North Korean Job Fraud Expands Beyond IT: New Sectors Targeted
MEDIUM
Threat Intel

North Korean Job Fraud Expands Beyond IT: New Sectors Targeted

DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.

Runtime Rebel Intel
5 min read · Sep 1, 2026
MEDIUM
Supply Chain

North Korea's Sapphire Sleet Targets Rust Supply Chain via arrayref Crate

North Korean actor Sapphire Sleet compromised a Rust maintainer's account to publish malicious `arrayref` crate versions, targeting the Rust supply chain.

Runtime Rebel Intel
4 min read · Aug 23, 2026
PurpleDelta: North Korean IT Workers Exploit Remote Hiring
MEDIUM
Threat Intel

PurpleDelta: North Korean IT Workers Exploit Remote Hiring

Recorded Future exposes PurpleDelta, North Korean IT workers using sophisticated fraudulent employment, AI, and extensive vetting evasion to fund DPRK military programs.

Runtime Rebel Intel
4 min read · Aug 18, 2026
HIGH
Threat Intel

North Korea Attribution, Data Breaches Impact OnTrac & UK Education

AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.

Runtime Rebel Intel
4 min read · Jul 31, 2026
PolinRider: North Korean Hackers Push 108 Malicious Packages
HIGH
Supply Chain

PolinRider: North Korean Hackers Push 108 Malicious Packages

Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.

Runtime Rebel Intel
4 min read · Jul 4, 2026
ScarCruft Deploys NarwhalRAT via Fake Microsoft Security Alerts
HIGH
Threat Intel

ScarCruft Deploys NarwhalRAT via Fake Microsoft Security Alerts

North Korean threat actor ScarCruft (APT37) is deploying NarwhalRAT via spear-phishing emails that mimic official Microsoft Account security notifications.

Runtime Rebel Intel
4 min read · Jun 16, 2026

Advertisement

North Korean APT Targets Developers via Malicious Tooling
HIGH
Threat Intel

North Korean APT Targets Developers via Malicious Tooling

North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.

Runtime Rebel Intel
4 min read · Jun 16, 2026
North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026
HIGH
Threat Intel

North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026

North Korean threat actors are projected to be responsible for 76% of all cryptocurrency stolen by 2026, utilizing sophisticated methods for large-scale heists.

Runtime Rebel Intel
4 min read · May 2, 2026
HIGH
Threat Intel

KelpDAO $290 Million Heist Linked to North Korea’s Lazarus Group

KelpDAO suffers a $290 million crypto-heist attributed to the North Korean Lazarus Group, highlighting ongoing threats to DeFi liquid restaking protocols.

Runtime Rebel Intel
4 min read · Apr 21, 2026
Sapphire Sleet's ClickFix: North Korea Targets macOS Users
HIGH
Threat Intel

Sapphire Sleet's ClickFix: North Korea Targets macOS Users

North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.

Runtime Rebel Intel
4 min read · Apr 16, 2026
APT37 Social Engineering via Facebook Delivers RokRAT Malware
HIGH
Threat Intel

APT37 Social Engineering via Facebook Delivers RokRAT Malware

North Korean threat actor APT37 leverages Facebook friend requests and trust-building to deploy the RokRAT trojan against high-value targets.

Runtime Rebel Intel
4 min read · Apr 13, 2026
HIGH
Supply Chain

North Korean Social Engineering Targets Node.js Maintainers

North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.

Runtime Rebel Intel
3 min read · Apr 6, 2026
UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise
HIGH
Supply Chain

UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise

Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Supply Chain

Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD

A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.

Runtime Rebel Intel
4 min read · Apr 1, 2026
Axios npm Supply Chain Attack Attributed to North Korea's UNC1069
HIGH
Supply Chain

Axios npm Supply Chain Attack Attributed to North Korea's UNC1069

Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.

Runtime Rebel Intel
4 min read · Apr 1, 2026
HIGH
Supply Chain

UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2

North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.

Runtime Rebel Intel
8 min read · Apr 1, 2026
WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware
HIGH
Threat Intel

WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware

North Korean threat actor WaterPlum leverages VS Code tasks.json to automate StoatWaffle malware deployment during fraudulent developer recruitment campaigns.

Runtime Rebel Intel
4 min read · Mar 23, 2026
HIGH
Threat Intel

Bitrefill Attributes Cyberattack to North Korean Lazarus Group

Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.

Runtime Rebel Intel
3 min read · Mar 19, 2026
UNC4899 Exploits AirDrop for Crypto Firm Breach — Analysis
HIGH
Threat Intel

UNC4899 Exploits AirDrop for Crypto Firm Breach — Analysis

UNC4899 breached a crypto firm using AirDrop to bypass network security. This analysis explores the TTPs of North Korean threat actors in 2025.

Runtime Rebel Intel
4 min read · Mar 9, 2026
HIGH
Threat Intel

North Korean APT Bridges Air Gaps with New Malware Suite

North Korean threat actors utilize malicious LNK files and specialized USB propagation tools to compromise air-gapped networks. Analysis and defense guide.

Runtime Rebel Intel
4 min read · Mar 2, 2026
HIGH
Threat Intel

APT37 Deploys SHROUDEDVUE Malware to Target Air-Gapped Networks

North Korean threat actor APT37 utilizes new malware families like SHROUDEDVUE and WASHSYNC to infiltrate air-gapped systems via removable USB drives.

Runtime Rebel Intel
4 min read · Feb 27, 2026
ScarCruft Ruby Jumper Campaign Targets Air-Gapped Networks
HIGH
Threat Intel

ScarCruft Ruby Jumper Campaign Targets Air-Gapped Networks

North Korean threat actor ScarCruft (APT37) deploys Ruby Jumper campaign using Zoho WorkDrive for C2 and USB malware to target air-gapped environments.

Runtime Rebel Intel
4 min read · Feb 27, 2026
HIGH
Threat Intel

Fake Recruiters Deploy Malware via Malicious Coding Challenges

North Korean threat actors are targeting software developers with fake job offers and malicious coding tests to deploy malware on developer workstations.

Runtime Rebel Intel
3 min read · Feb 27, 2026
Next.js Supply Chain Attacks: North Korean Actors Target Developers
HIGH
Supply Chain

Next.js Supply Chain Attacks: North Korean Actors Target Developers

North Korean state-sponsored actors leverage malicious Next.js repositories and fake job interviews to compromise developers' systems for persistent access and espionage.

Runtime Rebel Intel
4 min read · Feb 25, 2026