<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #North Korea</title><description>Cybersecurity articles tagged #North Korea on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>North Korean Job Fraud Expands Beyond IT: New Sectors Targeted</title><link>https://runtimerebel.com/blog/north-korean-job-fraud-expands-beyond-it-new-sectors-targeted</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-job-fraud-expands-beyond-it-new-sectors-targeted</guid><description>DPRK-linked threat actors are expanding job fraud beyond IT into healthcare, sales, and finance, leveraging AI and fake identities to fund illicit programs.</description><pubDate>Tue, 01 Sep 2026 02:38:21 GMT</pubDate><category>DPRK</category><category>North Korea</category><category>Insider Threat</category><category>AI</category><category>Job Fraud</category></item><item><title>North Korea&apos;s Sapphire Sleet Targets Rust Supply Chain via arrayref Crate</title><link>https://runtimerebel.com/blog/north-korea-s-sapphire-sleet-targets-rust-supply-chain-via-arrayref-crate</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-s-sapphire-sleet-targets-rust-supply-chain-via-arrayref-crate</guid><description>North Korean actor Sapphire Sleet compromised a Rust maintainer&apos;s account to publish malicious `arrayref` crate versions, targeting the Rust supply chain.</description><pubDate>Sun, 23 Aug 2026 16:16:30 GMT</pubDate><category>North Korea</category><category>Rust</category><category>Supply Chain Attack</category><category>Crates Io</category><category>Sapphire Sleet</category></item><item><title>PurpleDelta: North Korean IT Workers Exploit Remote Hiring</title><link>https://runtimerebel.com/blog/purpledelta-north-korean-it-workers-exploit-remote-hiring</link><guid isPermaLink="true">https://runtimerebel.com/blog/purpledelta-north-korean-it-workers-exploit-remote-hiring</guid><description>Recorded Future exposes PurpleDelta, North Korean IT workers using sophisticated fraudulent employment, AI, and extensive vetting evasion to fund DPRK military programs.</description><pubDate>Tue, 18 Aug 2026 16:25:57 GMT</pubDate><category>North Korea</category><category>State Sponsored</category><category>Supply Chain Risk</category><category>PurpleDelta</category><category>Fraudulent Employment</category></item><item><title>North Korea Attribution, Data Breaches Impact OnTrac &amp; UK Education</title><link>https://runtimerebel.com/blog/north-korea-attribution-data-breaches-impact-ontrac-uk-education</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-attribution-data-breaches-impact-ontrac-uk-education</guid><description>AWS attributes recent hacks to North Korea. OnTrac and the UK Department for Education report significant data breaches, impacting over 600,000 records.</description><pubDate>Fri, 31 Jul 2026 17:43:11 GMT</pubDate><category>North Korea</category><category>APT</category><category>Data Breach</category><category>Ontrac</category><category>UK Department for Education</category><category>AWS</category></item><item><title>PolinRider: North Korean Hackers Push 108 Malicious Packages</title><link>https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</link><guid isPermaLink="true">https://runtimerebel.com/blog/polinrider-north-korean-hackers-push-108-malicious-packages</guid><description>Analysis of the PolinRider campaign where North Korean actors published 108 malicious packages and extensions across npm, Go, and Chrome ecosystems.</description><pubDate>Sat, 04 Jul 2026 13:37:02 GMT</pubDate><category>PolinRider</category><category>Lazarus Group</category><category>NPM</category><category>Chrome Web Store</category><category>Supply Chain Attack</category><category>North Korea</category></item><item><title>ScarCruft Deploys NarwhalRAT via Fake Microsoft Security Alerts</title><link>https://runtimerebel.com/blog/scarcruft-deploys-narwhalrat-via-fake-microsoft-security-alerts</link><guid isPermaLink="true">https://runtimerebel.com/blog/scarcruft-deploys-narwhalrat-via-fake-microsoft-security-alerts</guid><description>North Korean threat actor ScarCruft (APT37) is deploying NarwhalRAT via spear-phishing emails that mimic official Microsoft Account security notifications.</description><pubDate>Tue, 16 Jun 2026 09:53:53 GMT</pubDate><category>ScarCruft</category><category>APT37</category><category>NarwhalRAT</category><category>North Korea</category><category>Phishing</category></item><item><title>North Korean APT Targets Developers via Malicious Tooling</title><link>https://runtimerebel.com/blog/north-korean-apt-targets-developers-via-malicious-tooling</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-apt-targets-developers-via-malicious-tooling</guid><description>North Korean threat cluster Contagious Interview exploits developer recruitment and code review phishing to deliver malware via tainted dev tools.</description><pubDate>Tue, 16 Jun 2026 01:12:25 GMT</pubDate><category>Contagious Interview</category><category>Famous Chollima</category><category>North Korea</category><category>APT</category><category>Phishing</category><category>Developer Tools</category><category>Supply Chain</category></item><item><title>North Korea Dominates Crypto Heists: 76% of Stolen Funds by 2026</title><link>https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korea-dominates-crypto-heists-76-of-stolen-funds-by-2026</guid><description>North Korean threat actors are projected to be responsible for 76% of all cryptocurrency stolen by 2026, utilizing sophisticated methods for large-scale heists.</description><pubDate>Sat, 02 May 2026 00:49:12 GMT</pubDate><category>North Korea</category><category>Cryptocurrency Theft</category><category>Lazarus Group</category><category>Cybercrime</category><category>Financial Crime</category><category>Nation State APT</category></item><item><title>KelpDAO $290 Million Heist Linked to North Korea’s Lazarus Group</title><link>https://runtimerebel.com/blog/kelpdao-290-million-heist-linked-to-north-koreas-lazarus-group</link><guid isPermaLink="true">https://runtimerebel.com/blog/kelpdao-290-million-heist-linked-to-north-koreas-lazarus-group</guid><description>KelpDAO suffers a $290 million crypto-heist attributed to the North Korean Lazarus Group, highlighting ongoing threats to DeFi liquid restaking protocols.</description><pubDate>Tue, 21 Apr 2026 00:44:39 GMT</pubDate><category>Lazarus Group</category><category>KelpDAO</category><category>DeFi</category><category>North Korea</category><category>Crypto Heist</category></item><item><title>Sapphire Sleet&apos;s ClickFix: North Korea Targets macOS Users</title><link>https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/sapphire-sleet-s-clickfix-north-korea-targets-macos-users</guid><description>North Korea-backed Sapphire Sleet is deploying ClickFix malware via fake job offers and phony Zoom updates to steal macOS user credentials and data.</description><pubDate>Thu, 16 Apr 2026 20:22:49 GMT</pubDate><category>Sapphire Sleet</category><category>ClickFix</category><category>macOS</category><category>North Korea</category><category>Phishing</category><category>Data Theft</category><category>APT</category></item><item><title>APT37 Social Engineering via Facebook Delivers RokRAT Malware</title><link>https://runtimerebel.com/blog/apt37-social-engineering-via-facebook-delivers-rokrat-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt37-social-engineering-via-facebook-delivers-rokrat-malware</guid><description>North Korean threat actor APT37 leverages Facebook friend requests and trust-building to deploy the RokRAT trojan against high-value targets.</description><pubDate>Mon, 13 Apr 2026 12:31:54 GMT</pubDate><category>APT37</category><category>Rokrat</category><category>Social Engineering</category><category>ScarCruft</category><category>North Korea</category></item><item><title>North Korean Social Engineering Targets Node.js Maintainers</title><link>https://runtimerebel.com/blog/north-korean-social-engineering-targets-node-js-maintainers</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-social-engineering-targets-node-js-maintainers</guid><description>North Korean threat actors use social engineering and malicious npm packages to target high-profile Node.js maintainers in a sophisticated supply chain campaign.</description><pubDate>Mon, 06 Apr 2026 12:24:38 GMT</pubDate><category>Lazarus Group</category><category>NPM</category><category>Social Engineering</category><category>Node Js</category><category>North Korea</category></item><item><title>UNC1069 Social Engineering Leads to Axios npm Supply Chain Compromise</title><link>https://runtimerebel.com/blog/unc1069-social-engineering-leads-to-axios-npm-supply-chain-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc1069-social-engineering-leads-to-axios-npm-supply-chain-compromise</guid><description>Runtime Rebel details how North Korean threat actor UNC1069 leveraged targeted social engineering against an Axios npm package maintainer, leading to a critical supply…</description><pubDate>Fri, 03 Apr 2026 16:16:04 GMT</pubDate><category>UNC1069</category><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>North Korea</category></item><item><title>Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD</title><link>https://runtimerebel.com/blog/axios-npm-supply-chain-attack-bypasses-github-actions-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-supply-chain-attack-bypasses-github-actions-ci-cd</guid><description>A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.</description><pubDate>Wed, 01 Apr 2026 12:28:22 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>North Korea</category><category>GitHub Actions</category><category>CI CD</category></item><item><title>Axios npm Supply Chain Attack Attributed to North Korea&apos;s UNC1069</title><link>https://runtimerebel.com/blog/axios-npm-supply-chain-attack-attributed-to-north-korea-s-unc1069</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-supply-chain-attack-attributed-to-north-korea-s-unc1069</guid><description>Google Threat Intelligence attributes a major Axios npm supply chain attack to North Korean group UNC1069, emphasizing risks to developer environments.</description><pubDate>Wed, 01 Apr 2026 08:34:33 GMT</pubDate><category>UNC1069</category><category>NPM</category><category>Axios</category><category>North Korea</category><category>Supply Chain Security</category></item><item><title>UNC1069 Leverages Axios NPM Supply Chain to Deploy WAVESHAPER.V2</title><link>https://runtimerebel.com/blog/unc1069-leverages-axios-npm-supply-chain-to-deploy-waveshaper-v2</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc1069-leverages-axios-npm-supply-chain-to-deploy-waveshaper-v2</guid><description>North Korea-nexus UNC1069 compromised widely used Axios NPM package (v1.14.1, 0.30.4) by injecting plain-crypto-js to deploy WAVESHAPER.V2 backdoor across multiple OS.</description><pubDate>Wed, 01 Apr 2026 00:45:35 GMT</pubDate><category>UNC1069</category><category>WAVESHAPER V2</category><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>Plain Crypto Js</category><category>SILKBELL</category><category>North Korea</category></item><item><title>WaterPlum Abuses VS Code Tasks to Deploy StoatWaffle Malware</title><link>https://runtimerebel.com/blog/waterplum-abuses-vs-code-tasks-to-deploy-stoatwaffle-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/waterplum-abuses-vs-code-tasks-to-deploy-stoatwaffle-malware</guid><description>North Korean threat actor WaterPlum leverages VS Code tasks.json to automate StoatWaffle malware deployment during fraudulent developer recruitment campaigns.</description><pubDate>Mon, 23 Mar 2026 20:17:05 GMT</pubDate><category>Stoatwaffle</category><category>Waterplum</category><category>Visual Studio Code</category><category>North Korea</category><category>Lazarus Group</category></item><item><title>Bitrefill Attributes Cyberattack to North Korean Lazarus Group</title><link>https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</link><guid isPermaLink="true">https://runtimerebel.com/blog/bitrefill-attributes-cyberattack-to-north-korean-lazarus-group</guid><description>Bitrefill identifies North Korean Lazarus Group as the perpetrator of a recent cyberattack, underscoring the persistent threat to crypto-focused businesses.</description><pubDate>Thu, 19 Mar 2026 20:16:23 GMT</pubDate><category>Lazarus Group</category><category>BlueNoroff</category><category>Bitrefill</category><category>Cryptocurrency</category><category>APT</category><category>North Korea</category></item><item><title>UNC4899 Exploits AirDrop for Crypto Firm Breach — Analysis</title><link>https://runtimerebel.com/blog/unc4899-exploits-airdrop-for-crypto-firm-breach-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/unc4899-exploits-airdrop-for-crypto-firm-breach-analysis</guid><description>UNC4899 breached a crypto firm using AirDrop to bypass network security. This analysis explores the TTPs of North Korean threat actors in 2025.</description><pubDate>Mon, 09 Mar 2026 16:30:09 GMT</pubDate><category>UNC4899</category><category>Jade Sleet</category><category>macOS Security</category><category>AirDrop</category><category>North Korea</category><category>Cryptocurrency</category></item><item><title>North Korean APT Bridges Air Gaps with New Malware Suite</title><link>https://runtimerebel.com/blog/north-korean-apt-bridges-air-gaps-with-new-malware-suite</link><guid isPermaLink="true">https://runtimerebel.com/blog/north-korean-apt-bridges-air-gaps-with-new-malware-suite</guid><description>North Korean threat actors utilize malicious LNK files and specialized USB propagation tools to compromise air-gapped networks. Analysis and defense guide.</description><pubDate>Mon, 02 Mar 2026 12:18:34 GMT</pubDate><category>Lazarus Group</category><category>Air Gapped</category><category>LNK Malware</category><category>North Korea</category><category>USB Propagation</category></item><item><title>APT37 Deploys SHROUDEDVUE Malware to Target Air-Gapped Networks</title><link>https://runtimerebel.com/blog/apt37-deploys-shroudedvue-malware-to-target-air-gapped-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/apt37-deploys-shroudedvue-malware-to-target-air-gapped-networks</guid><description>North Korean threat actor APT37 utilizes new malware families like SHROUDEDVUE and WASHSYNC to infiltrate air-gapped systems via removable USB drives.</description><pubDate>Fri, 27 Feb 2026 20:12:14 GMT</pubDate><category>APT37</category><category>ScarCruft</category><category>SHROUDEDVUE</category><category>Air Gap</category><category>North Korea</category><category>WASHSYNC</category></item><item><title>ScarCruft Ruby Jumper Campaign Targets Air-Gapped Networks</title><link>https://runtimerebel.com/blog/scarcruft-ruby-jumper-campaign-targets-air-gapped-networks</link><guid isPermaLink="true">https://runtimerebel.com/blog/scarcruft-ruby-jumper-campaign-targets-air-gapped-networks</guid><description>North Korean threat actor ScarCruft (APT37) deploys Ruby Jumper campaign using Zoho WorkDrive for C2 and USB malware to target air-gapped environments.</description><pubDate>Fri, 27 Feb 2026 16:15:18 GMT</pubDate><category>ScarCruft</category><category>APT37</category><category>Ruby Jumper</category><category>Zoho WorkDrive</category><category>Air Gapped</category><category>Zscaler</category><category>North Korea</category></item><item><title>Fake Recruiters Deploy Malware via Malicious Coding Challenges</title><link>https://runtimerebel.com/blog/fake-recruiters-deploy-malware-via-malicious-coding-challenges</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-recruiters-deploy-malware-via-malicious-coding-challenges</guid><description>North Korean threat actors are targeting software developers with fake job offers and malicious coding tests to deploy malware on developer workstations.</description><pubDate>Fri, 27 Feb 2026 12:18:39 GMT</pubDate><category>Lazarus Group</category><category>North Korea</category><category>Social Engineering</category><category>Malicious Coding Challenges</category><category>Cryptocurrency</category><category>Trojanized Software</category></item><item><title>Next.js Supply Chain Attacks: North Korean Actors Target Developers</title><link>https://runtimerebel.com/blog/next-js-supply-chain-attacks-north-korean-actors-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/next-js-supply-chain-attacks-north-korean-actors-target-developers</guid><description>North Korean state-sponsored actors leverage malicious Next.js repositories and fake job interviews to compromise developers&apos; systems for persistent access and espionage.</description><pubDate>Wed, 25 Feb 2026 20:16:34 GMT</pubDate><category>Next Js</category><category>Software Supply Chain Attack</category><category>North Korea</category><category>Lazarus Group</category><category>Developers</category><category>Fake Job Scams</category><category>Persistent Access</category><category>Malware</category></item><item><title>Lazarus Group Shifts to Medusa Ransomware &amp; Multi-Tool Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-shifts-to-medusa-ransomware-multi-tool-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-shifts-to-medusa-ransomware-multi-tool-attacks</guid><description>North Korea&apos;s Lazarus Group now employs Medusa ransomware, Comebacker backdoor, Blindingcan RAT, and Infohook info stealer in recent attacks, signaling an evolving…</description><pubDate>Wed, 25 Feb 2026 04:43:37 GMT</pubDate><category>Lazarus Group</category><category>Medusa Ransomware</category><category>Comebacker</category><category>Blindingcan RAT</category><category>Infohook</category><category>North Korea</category><category>Ransomware</category><category>APT</category></item><item><title>Lazarus Group Deploys Medusa Ransomware in Global Healthcare Attacks</title><link>https://runtimerebel.com/blog/lazarus-group-deploys-medusa-ransomware-in-global-healthcare-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/lazarus-group-deploys-medusa-ransomware-in-global-healthcare-attacks</guid><description>Lazarus Group (Diamond Sleet) targets Middle Eastern entities and U.S. healthcare with Medusa ransomware, according to Symantec and Carbon Black reports.</description><pubDate>Tue, 24 Feb 2026 12:21:18 GMT</pubDate><category>Lazarus Group</category><category>Medusa Ransomware</category><category>Diamond Sleet</category><category>Pompilus</category><category>Healthcare Security</category><category>North Korea</category></item></channel></rss>