Related Threat Clusters
-
DPRK-Linked Malware Targeting Job Seekers via Wellfound
A cybersecurity incident involved a fake job interview scheme on Wellfound, where an operator named 'Felix' from 'HyperHive' targeted an individual using a social engineering tactic referencing their real CV. The attack…
2 articles · Updated April 7, 2026 -
Persistent Firestarter Malware Targets Cisco Firepower Devices in US Agencies
A sophisticated backdoor malware named Firestarter has been discovered on Cisco Firepower devices, attributed to the state-sponsored threat actor UAT-4356. The malware exploits two vulnerabilities, CVE-2025-20333 and…
37 articles · Updated April 23, 2026 -
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
In early 2026, the Iranian APT group MuddyWater launched cyberattacks against U.S. banking, a major airport, and Israeli operations of a U.S.-based software company. The attacks intensified in March, coinciding with…
16 articles · Updated July 22, 2026 -
North Korean Hackers Utilize EtherHiding for Cryptocurrency Theft
The Google Threat Intelligence Group (GTIG) reports that North Korean threat actor UNC5342 has adopted a new technique called EtherHiding to deliver malware and facilitate cryptocurrency theft. This method embeds…
3 articles · Updated May 26, 2026 -
Void Dokkaebi's Malware Campaign Exploits Developer Repositories via Fake Job Interviews
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
22 articles · Updated April 22, 2026 -
North Korean Hackers Use SVG Steganography in Job Scam Malware Campaign
DPRK-aligned hackers have launched a campaign known as Contagious Interview, utilizing steganography to hide malware within SVG flag images. This malware targets developers through fake job postings and coding…
4 articles · Updated July 19, 2026 -
Mini Shai-Hulud Supply Chain Attack Targets SAP npm Packages
A new supply chain attack, dubbed 'Mini Shai-Hulud', has compromised multiple npm packages related to SAP's Cloud Application Programming Model (CAP). This attack involves injecting malicious preinstall scripts into…
751 articles · Updated April 29, 2026 -
Spring Ring: Voice Phishing Campaigns Target Microsoft Teams Users
Between January and April 2026, a coordinated voice phishing campaign named 'Spring Ring' targeted over 150 employees across 10 companies, using Microsoft Teams to impersonate IT help desk personnel. Attackers employed…
3 articles · Updated August 31, 2026 -
GitHub Breach: 3,800 Internal Repositories Compromised via Malicious VS Code Extension
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
149 articles · Updated May 20, 2026 -
North Korea-linked EtherRAT Malware Exploits React2Shell Vulnerability
North Korea-linked hackers have exploited a critical flaw in web applications using a new malware called EtherRAT. This remote access trojan employs Ethereum smart contracts for communication and utilizes multiple Linux…
3 articles · Updated December 10, 2025
Recent Intelligence Reports
- Communication Channel Identity Risks — unit42.paloaltonetworks.com · August 31, 2026
- 739165 — www.cybersecuritydive.com · August 11, 2026
- 002 — attack.mitre.org · July 23, 2026
- 001 — attack.mitre.org · July 23, 2026
- Contagious Interview Malware Svg Steganography — www.elastic.co · July 20, 2026
- Fake Coding Tests Deliver OtterCookie — Thehackernews · July 17, 2026
- North Korean hackers expand supply chain attack campaign across ecosystems — Ground.News · July 3, 2026
- North Korean hackers expand supply chain attack campaign across ecosystems — Nknews · July 3, 2026