In 2025, cryptocurrency thefts have surged significantly, with over $2 billion stolen in just the first half of the year, marking a 17.27% increase compared to 2022. The ByBit hack, attributed to North Korean state…
Bybit has filed a civil lawsuit against North Korea, its Reconnaissance General Bureau, and the Lazarus Group, accusing them of orchestrating a $1.5 billion hack in February 2025. The lawsuit, filed in the U.S. District…
In 2025 and the first half of 2026, North Korea's Lazarus Group has been a major threat in the cryptocurrency sector, responsible for approximately $6.75 billion in theft. The group has exploited vulnerabilities in the…
Void Dokkaebi, a North Korean threat actor, has escalated its malware distribution tactics by using fake job interviews to compromise software developers. This campaign, known as the 'Contagious Interview,' targets…
Grinex, a Kyrgyzstan-based cryptocurrency exchange linked to Russia, suspended its operations following a cyberattack that resulted in the theft of over 1 billion rubles (approximately $13 million). The attack, which…
On May 26, 2026, the UK imposed sanctions on 18 entities, including crypto exchanges and banks, linked to the Kremlin-backed A7 network, which allegedly facilitated over $90 billion in financial transactions to support…
The US Department of Justice and the Treasury have launched a coordinated crackdown on Southeast Asian scam centers, resulting in criminal charges against multiple individuals, including a Cambodian senator. The Scam…
Microsoft Threat Intelligence has reported a new malware campaign utilizing the BNB Smart Chain, employing a technique called EtherHiding. This method allows hackers to store malicious code within blockchain smart…
On July 1, 2026, the U.S. Treasury's OFAC sanctioned 134 cryptocurrency addresses linked to ISIS-K, including 131 TRON wallets. Tether responded by freezing all balances on these wallets, which had received over $1.4…
On July 28, 2026, two beta releases of Joyfill npm packages, @joyfill/layouts and @joyfill/components, were found to deliver the DEV#POPPER remote access trojan (RAT) and a credential stealer. The malware executes upon…