FAMOUS CHOLLIMA is a apt_group tracked across 11 threat clusters and 17 intelligence report mentions on ThreatCluster. First observed November 4, 2025; most recent activity July 21, 2026.
Malicious npm packages have been identified as vehicles for the PylangGhost remote access trojan (RAT), linked to North Korean state-sponsored group FAMOUS CHOLLIMA. The attack began with the release of compromised…
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
The Cloud Atlas APT group has been observed employing a sophisticated cyber espionage campaign targeting government and commercial entities in Russia and Belarus. This campaign, active since 2025 and continuing into…
A malicious npm package named @validate-sdk/v2, introduced through Anthropic’s Claude Opus AI model, has been linked to a breach in the open-source crypto trading project openpaw-graveyard. This malware, dubbed…
Researchers at SOCRadar have identified a new social engineering campaign by North Korea's Famous Chollima group, targeting Web3 and cryptocurrency professionals. The operation, dubbed ClickFake, employs fraudulent job…
The North Korea-linked threat group Void Dokkaebi has enhanced its InvisibleFerret malware by converting it from readable Python scripts to compiled binary modules (.pyd and .so files). This upgrade makes it more…
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
A new malware campaign is targeting macOS users with the AMOS-linked Atomic Stealer, exploiting fake software update pages and the built-in Script Editor application. Victims are tricked into executing malicious…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
On November 19, 2025, the United States, United Kingdom, and Australia announced coordinated sanctions against the Russian web company Media Land, accusing it of facilitating ransomware operations. The sanctions include…