Related Threat Clusters
-
NPM Packages Distribute PylangGhost RAT in Supply Chain Attack
Malicious npm packages have been identified as vehicles for the PylangGhost remote access trojan (RAT), linked to North Korean state-sponsored group FAMOUS CHOLLIMA. The attack began with the release of compromised…
4 articles · Updated March 17, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
Cloud Atlas APT Group Exploits CVE-2018-0802 and Modifies termsrv.dll for RDP Access
The Cloud Atlas APT group has been observed employing a sophisticated cyber espionage campaign targeting government and commercial entities in Russia and Belarus. This campaign, active since 2025 and continuing into…
4 articles · Updated May 25, 2026 -
North Korean Malware Targets Crypto Developers via NPM Packages
A malicious npm package named @validate-sdk/v2, introduced through Anthropic’s Claude Opus AI model, has been linked to a breach in the open-source crypto trading project openpaw-graveyard. This malware, dubbed…
6 articles · Updated May 1, 2026 -
North Korean PurpleDelta Network Exploits Remote Hiring for Fraudulent Employment
Insikt Group has identified PurpleDelta, a North Korean IT worker network, employing over 22 fabricated personas to apply for jobs at more than 1,100 companies, likely securing positions at ten or more organizations.…
3 articles · Updated August 19, 2026 -
North Korean ClickFake Campaign Targets Web3 Professionals with RATs
Researchers at SOCRadar have identified a new social engineering campaign by North Korea's Famous Chollima group, targeting Web3 and cryptocurrency professionals. The operation, dubbed ClickFake, employs fraudulent job…
2 articles · Updated July 22, 2026 -
Void Dokkaebi Upgrades InvisibleFerret Malware to Evade Detection
The North Korea-linked threat group Void Dokkaebi has enhanced its InvisibleFerret malware by converting it from readable Python scripts to compiled binary modules (.pyd and .so files). This upgrade makes it more…
2 articles · Updated May 25, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
753 articles · Updated April 29, 2026 -
New macOS Malware Campaign Targets Users via Fake Updates and Script Editor
A new malware campaign is targeting macOS users with the AMOS-linked Atomic Stealer, exploiting fake software update pages and the built-in Script Editor application. Victims are tricked into executing malicious…
43 articles · Updated April 9, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026
Recent Intelligence Reports
- PurpleDelta's Fraudulent Employment Operations — Recordedfuture · August 18, 2026
- Researchers Uncover North Korean 'ClickFake' Campaign Targeting Web3 Pros — Infosecurity-Magazine · July 21, 2026
- North Korean hackers expand supply chain attack campaign across ecosystems — Ground.News · July 3, 2026
- AI Coding Agents Skip Package Verification, and Attackers Are Exploiting It — Techtimes · July 1, 2026
- InvisibleFerret Malware Now Ships as .pyd and .so Files to Evade Script Detection — Cybersecuritynews · May 25, 2026
- APT Group Patches termsrv.dll to Enable Multiple RDP Sessions — Gbhackers · May 25, 2026
- InvisibleFerret Malware Uses .pyd and .so Files to Evade Script Detection — Gbhackers · May 25, 2026
- GitHub confirms 3,800 internal repos stolen through poisoned VS Code extension as supply ... — Venturebeat · May 20, 2026