Click here to download all references as Bib-File.•
| 2026-07-24
⋅
JUMPSEC LABS
⋅
Inside a DPRK BlueNoroff ClickFix Kit |
| 2026-07-24
⋅
Daily NK
⋅
North Korea busts elite hacking ring inside its own banks |
| 2026-07-24
⋅
Nokia
⋅
Jackskid's residential proxy, brought to you by UPnP Jackskid |
| 2026-07-23
⋅
NSA
⋅
NSA and Partners Alert Zimbra Collaboration Suite Users of a Russian State-Supported Phishing Campaign ZimReaper |
| 2026-07-23
⋅
Proofpoint
⋅
Operation RoundPress Rolls on with More Half-Click Webmail Zero-Days from TA458 SpyPress |
| 2026-07-23
⋅
Proofpoint
⋅
TA488 Targets Zimbra Mailservers with Half-Click Exploits ZimReaper |
| 2026-07-23
⋅
Group-IB
⋅
JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake AdaptixC2 reGeorg |
| 2026-07-22
⋅
Prophet Security
⋅
EtherHiding Malware on macOS: How Attackers Hide C2 on the Blockchain |
| 2026-07-22
⋅
Huntress Labs
⋅
Inside FakeAgent: How a Claude Desktop Malvertising Campaign Hit 29 Organizations with SectopRAT SectopRAT |
| 2026-07-22
⋅
bluecyber
⋅
Beyond the Archive: CVE-2025-8088 Stealer Targeting Ukraine GIFTEDCROOK |
| 2026-07-21
⋅
kienmanowar Blog
⋅
[QuickNote] Mustang Panda ToneShell (APT S1239) Beacon Shellcode – RE Analysis TONESHELL |
| 2026-07-21
⋅
DTEX
⋅
From Payroll to Pyongyang: The DPRK IT Worker Money Trail |
| 2026-07-21
⋅
ANY.RUN
⋅
SnappyClient Analysis SnappyClient |
| 2026-07-20
⋅
Medium Ireneusz Tarnowski
⋅
INC Ransom: Infrastructure Analysis, Operational Tradecraft, and Detection Opportunities INC INC |
| 2026-07-18
⋅
Github (muhammadzidane632)
⋅
Hopeless Hopeless |
| 2026-07-17
⋅
OpenSourceMalware
⋅
ChainVeil and ViteVenom are DPRK’s PolinRider Campaign JADESNOW |
| 2026-07-17
⋅
Elastic
⋅
New North Korean campaign uses fake coding interviews to steal developer credentials OtterCookie |
| 2026-07-15
⋅
Zscaler
⋅
ClaudeFix: Shared Claude Chats Meet ClickFix MacSync |
| 2026-07-15
⋅
OpenSourceMalware
⋅
PolinRider Confirmed Footprint Grows 6.5x Since March JADESNOW |
| 2026-07-15
⋅
Expel
⋅
Introducing CylindricalCanine: The GoldenEyeDog subgroup responsible for the April DigiCert incident Ghost RAT |