BlueNoroff is a apt_group tracked across 11 threat clusters and 19 intelligence report mentions on ThreatCluster. First observed October 28, 2025; most recent activity June 26, 2026.
A sophisticated malware campaign targeting macOS users has been linked to North Korean threat group Sapphire Sleet. This operation focuses on cryptocurrency organizations, venture capital firms, and Web3 developers.…
Bitrefill, a crypto e-commerce platform, disclosed a cyberattack that began on March 1, 2026, attributed to North Korea's Lazarus Group. The breach started with a compromised employee laptop, allowing attackers to…
North Korea's BlueNoroff group is executing a sophisticated campaign against cryptocurrency executives, utilizing fake Zoom meetings enhanced with AI-generated avatars and stolen video footage. The attacks primarily…
A previously undocumented surveillance framework, Canis C2, has been identified targeting Japan. The investigation began when researchers discovered a phishing Android application masquerading as Paidy, a…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
On June 25, 2026, Polymarket confirmed a security breach that led to the theft of approximately $3 million from fewer than 15 user accounts. The attack was executed through a compromised third-party vendor, which…
A new variant of the MacSync stealer malware has been identified, exploiting Apple's notarization process to bypass security measures on macOS devices. This malware poses a risk to sensitive user data by disguising…
North Korea-aligned threat actor BlueNoroff has initiated two new campaigns, GhostCall and GhostHire, targeting fintech executives and Web3 developers. These campaigns utilize social engineering tactics on platforms…
Google's Mandiant security team reported that North Korean hackers, identified as UNC1069 or 'CryptoCore', are employing AI-generated deepfakes in fraudulent video meetings to target cryptocurrency companies. The…
Security researchers from LayerX have identified vulnerabilities in OpenAI's Atlas browser that enable attackers to inject malicious code into the browser's memory. This flaw allows for remote code execution and the…