<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Last Week in DPRK Cyber</title><link>https://lastweek.lazarus.day/</link><description>Recent content on lastweek.lazarus.day</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><copyright>© 2021–2026 by lazarusholic is licensed under [CC BY-SA 4.0](https://creativecommons.org/licenses/by-sa/4.0/) Creative Commons Attribution Share Alike</copyright><lastBuildDate>Mon, 10 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lastweek.lazarus.day/index.xml" rel="self" type="application/rss+xml"/><item><title>LW32: AI adoption, developer compromise, and IT worker exposure</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w32/</link><pubDate>Mon, 10 Aug 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w32/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting covered DPRK activity against developers, software supply chains, and remote hiring. Genians found <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> infrastructure running local AI tools and document retrieval software. CrowdStrike attributed the poisoning of 131 AI framework packages to <a href="https://lazarus.day/actors/stardustchollima/">STARDUST CHOLLIMA</a>, while an investigation into North Korean command-and-control servers found evidence of intrusions at hundreds of organizations.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting covered DPRK activity against developers, software supply chains, and remote hiring. Genians found <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> infrastructure running local AI tools and document retrieval software. CrowdStrike attributed the poisoning of 131 AI framework packages to <a href="https://lazarus.day/actors/stardustchollima/">STARDUST CHOLLIMA</a>, while an investigation into North Korean command-and-control servers found evidence of intrusions at hundreds of organizations.</p>
<p>Researchers also placed DPRK-linked IT workers inside a controlled DeFi company and recorded their remote-access tools, VPN use, job-application services, and account synchronization. AhnLab connected current Xctdoor distribution with older CRAT operations attributed by other firms to <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>, though the current campaign was not directly attributed on that basis. Reports on device surveillance and smishing inside North Korea concerned domestic control and crime rather than an external state-directed campaign.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-kimsuky-adds-ai-tools-to-established-attack-methods">1. Kimsuky adds AI tools to established attack methods</h3>
<p>Genians linked Operation GitPower to <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> through linguistic artifacts, overlap with earlier campaigns, and infrastructure behavior. The operation uses spearphishing, malicious LNK files, obfuscated PowerShell, scheduled tasks, and Git repositories to collect system information and deliver encrypted AsyncRAT payloads.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup><sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<p>Logs from the infrastructure recorded Ollama, GPT4All, and Msty installations. The operators also configured document-based retrieval augmented generation and collected libraries for AI agents, external model integration, and speech-to-text processing. The evidence points to work with existing models, not the training of a proprietary model. Plausible uses include preparing lures, analyzing stolen data, and assisting malware development, but the observed installations do not establish how extensively the tools were used in live operations.</p>
<h3 id="2-developers-remain-both-an-access-route-and-a-supply-chain-target">2. Developers remain both an access route and a supply-chain target</h3>
<p>Researcher Vangelis Stykas told Wired that 22 months of access to North Korean command-and-control servers exposed evidence affecting 1,640 companies in 57 countries. He assessed that 700 to 800 organizations suffered serious intrusions involving root access to servers, AWS environments, or cryptocurrency wallets. Much of the activity relied on <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a>, which uses fake job offers and malicious coding tests, as well as fraudulent remote employment by North Korean IT workers.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
<p>CrowdStrike separately attributed the poisoning of 131 AI framework packages to <a href="https://lazarus.day/actors/stardustchollima/">STARDUST CHOLLIMA</a>. The package campaign sought access through components trusted by developers, creating a route into downstream systems. These reports describe distinct operations, but both exploit routine developer work: evaluating code from a recruiter and importing software into a project.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<h3 id="3-a-controlled-workplace-exposed-it-worker-tradecraft">3. A controlled workplace exposed IT worker tradecraft</h3>
<p>BCA LTD, NorthScan, and ANY.RUN recruited operators they identified as DPRK-linked <a href="https://lazarus.day/actors/famouschollima/">Famous Chollima</a> IT workers into a simulated DeFi company. Monitored Windows sandboxes recorded screen activity, files, and network requests. The workers used AnyDesk and Chrome Remote Desktop, Astrill VPN, one-time-password services, synchronized Google accounts, and automated job-application tools.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup></p>
<p>The researchers observed four Astrill VPN nodes and a residential address in Vladivostok. They connected the latter through an associated individual and logistics company to prior reporting on North Korean connectivity and IT worker activity. That association is an investigative lead rather than proof of each operator&rsquo;s physical location. The presentation also traced clusters of similar company websites, suspected shell-company arrangements, and cryptocurrency services used to move earnings.</p>
<h3 id="4-xctdoor-activity-overlaps-with-older-crat-operations">4. Xctdoor activity overlaps with older CRAT operations</h3>
<p>AhnLab connected <a href="https://lazarus.day/actors/larva-26005/">Larva-26005</a>&rsquo;s recent Xctdoor distribution to CRAT attacks against South Korean users dating to 2020. Shared AppX installation paths, runtime code obfuscation, and the earlier deployment of CRAT, Xctdoor, and Hansom ransomware on the same systems support the connection. Other security firms attributed the older CRAT activity to <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>, so the finding does not amount to a new direct attribution of the current campaign.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup><sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<p>The 2026 activity delivered C++ and Go variants of Xctdoor through fake Veraport and SoftCamp installers and malicious LNK files. Related activity abused compromised IIS servers, groupware upload pages, ERP update components, and a trojanized BeeBEEP installer. Xctdoor can run shell commands, transfer files, capture keystrokes and screenshots, monitor the clipboard, and inject payloads into memory.</p>
<h3 id="5-domestic-surveillance-and-fraud-require-separate-treatment">5. Domestic surveillance and fraud require separate treatment</h3>
<p>A DEF CON presentation described controls built into North Korean Android devices. TraceViewer captures a screenshot every five minutes, while RedFlag deletes transferred files that lack an approved cryptographic signature. State-run distribution points, network isolation, radio detection, device searches, and physical punishment reinforce these technical restrictions. The Pigeon tool counters one part of the system by self-signing media so it can pass RedFlag checks.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup></p>
<p>Daily NK separately reported the arrest of two state-trained IT specialists accused of stealing from North Korean donju through smishing and voice phishing. The suspects allegedly impersonated the central bank and inspection agencies, stole Jonsong payment credentials, and used family information in extortion calls. The case describes domestic criminal use of state-developed skills. It does not establish direction by a DPRK external cyber unit.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Development teams should isolate coding tests from unknown recruiters and review newly introduced packages before they reach build systems. Remote-hiring checks should compare identity documents, access location, payment ownership, interview behavior, and remote-control software. Account synchronization on managed workstations deserves attention because it can expose credentials and browsing data beyond the immediate session.</p>
<p>Endpoint monitoring should flag malicious LNK execution, unexpected scheduled tasks, fake enterprise-software installers, and payload retrieval from public code repositories. South Korean organizations using Veraport, SoftCamp, groupware, or ERP update components should also check for unauthorized installers and abnormal child processes.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.genians.co.kr/blog/threat_intelligence/kimsuky_ai_llm">AI를 공격 체계에 접목하는 김수키, 미끼 문서 제작부터 로컬 LLM 구축까지</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://www.genians.co.kr/en/blog/threat_intelligence/kimsuky_ai_llm">Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://www.wired.com/story/a-security-pro-hacked-north-korean-hackers-he-found-theyd-breached-hundreds-of-networks-worldwide/">A Security Pro Hacked North Korean Hackers. He Found They’d Breached Hundreds of Networks Worldwide</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://www.crowdstrike.com/en-us/resources/reports/threat-hunting-report">2026 Threat Hunting Report</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20Heiner%20Garc%C3%ADa%2C%20Mauro%20Eldritch%20-%20Smile%2C%20you%27re%20on%20camera%20Livestreaming%20from%20North%20Korea%27s%20IT%20workers%20laptop%20farm%20-%20Are%20v2.pdf">SMILE, YOU&rsquo;RE ON CAMERA!</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://asec.ahnlab.com/en/94847">Analysis of the Connection Between Xctdoor and Past CRAT Attack Cases (Larva-26005)</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://asec.ahnlab.com/ko/94846">Xctdoor와 과거 CRAT 공격 사례의 연관성 분석 (Larva-26005)</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://media.defcon.org/DEF%20CON%2034/DEF%20CON%2034%20presentations/DEF%20CON%2034%20presentations/DEF%20CON%2034%20-%20JDT%20-%20Cracking%20North%20Korea%27s%20Information%20Control%20How%20Smugglers%2C%20Defectors%2C%20and%20Technologists%20are%20Breaking%20Open%20the%20World%27s%20Most%20Locked-D.pdf">Cracking North Korea’s Information Control</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://www.dailynk.com/english/wonsan-smishing-voice-phishing-donju-arrests/">Two arrested in Wonsan for smishing, voice phishing crimes targeting donju</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW31: Package compromise, watering holes, and developer-led theft</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w31/</link><pubDate>Mon, 03 Aug 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w31/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s DPRK-related reporting focused on open-source compromise, blockchain-based command delivery, and attacks through trusted South Korean websites and security software. Supply-chain campaigns first compromised developers or maintainers, then pushed malicious code into legitimate npm packages and Go modules. Separate research documented <a href="https://lazarus.day/actors/apt37/">APT37</a>&rsquo;s NarwhalRAT infrastructure and an AFX bridge theft attributed in a detailed post-mortem to <a href="https://lazarus.day/actors/unc4899/">UNC4899</a> / <a href="https://lazarus.day/actors/tradertraitor/">TraderTraitor</a>.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s DPRK-related reporting focused on open-source compromise, blockchain-based command delivery, and attacks through trusted South Korean websites and security software. Supply-chain campaigns first compromised developers or maintainers, then pushed malicious code into legitimate npm packages and Go modules. Separate research documented <a href="https://lazarus.day/actors/apt37/">APT37</a>&rsquo;s NarwhalRAT infrastructure and an AFX bridge theft attributed in a detailed post-mortem to <a href="https://lazarus.day/actors/unc4899/">UNC4899</a> / <a href="https://lazarus.day/actors/tradertraitor/">TraderTraitor</a>.</p>
<p>The package and watering-hole reports exposed recurring reliance on trusted access. Developers imported poisoned components, website visitors loaded vulnerable security software, and a DeFi developer cloned a repository offered through a fake job approach. IT worker alerts treated remote employment as both a sanctions-evasion channel and an insider risk.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-automated-compromise-spread-through-npm-and-go">1. Automated compromise spread through npm and Go</h3>
<p><a href="https://lazarus.day/actors/polinrider/">PolinRider</a> poisoned packages and Go modules after compromising developer systems, apparently spreading to projects the victims could access rather than selecting only high-value targets. Twenty analyzed packages shared XOR keys, TRON wallets, a fake font loader, and an automated propagation script. Attackers backdated malicious Go commits, and deleted modules remained available through Go&rsquo;s permanent proxy cache.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p>Two Joyfill beta packages ran an obfuscated loader when imported, not during installation. The chain followed transactions across Tron, Aptos, and BNB Smart Chain, then delivered a <a href="https://lazarus.day/actors/devpopper/">DEV#POPPER</a>-style RAT and credential stealer. The code and protocol overlapped with <a href="https://lazarus.day/actors/polinrider/">PolinRider</a>, but the three research teams did not uniformly attribute the Joyfill compromise itself.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup><sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup><sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<p>Amazon attributed several npm compromises, including Axios, to a DPRK-linked actor with medium confidence. Google&rsquo;s mitigation guidance recommended release cooldowns, private registries, disabled lifecycle scripts, ephemeral CI runners, short-lived credentials, provenance checks, and strict outbound controls.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup><sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup></p>
<h3 id="2-blockchain-records-carried-changing-c2-information">2. Blockchain records carried changing C2 information</h3>
<p>A ClickFix operation used a fake macOS update page to make victims paste a Node.js command into Terminal. The implant read rotating C2 details from Ethereum contracts, collected wallet, browser, developer, and cloud credentials, and installed a malicious Chrome extension. Wallet and infrastructure links matched DPRK-linked <a href="https://lazarus.day/actors/unc5342/">UNC5342</a> and <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> activity.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<p>NullReceiver removed the smart contract. Trojanized npm packages looked up the attacker&rsquo;s latest zero-value Ethereum transfer and decoded an IP address from the recipient address. This reduced the fixed transaction features defenders could fingerprint. Joyfill&rsquo;s loader likewise walked transactions on several chains to find later stages.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup><sup id="fnref1:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup><sup id="fnref1:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup><sup id="fnref1:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<h3 id="3-apt37-paired-spearphishing-with-cloud-dead-drops">3. APT37 paired spearphishing with cloud dead drops</h3>
<p>WhoisXML API analyzed an <a href="https://lazarus.day/actors/apt37/">APT37</a> campaign that delivered the Python-based NarwhalRAT through spearphishing and malicious LNK files. The RAT supported keylogging, screen capture, USB collection, and remote command execution. Its operators used a South Korean relay server and the pCloud API as a dead-drop resolver.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<p>Infrastructure expansion from five domains and six IP addresses produced 888 connected artifacts, but the researchers said those additional domains had not been weaponized. They are investigative leads, not confirmed campaign infrastructure.</p>
<h3 id="4-trusted-websites-and-security-software-delivered-backdoors">4. Trusted websites and security software delivered backdoors</h3>
<p>South Korean investigations described compromised websites that exploited vulnerable electronic-signature, authentication, and keyboard-security components. The chains installed DLL backdoors or memory-resident RATs without requiring the user to launch a file, then used credential dumping, RDP movement, reverse SSH tunnels, and anti-forensic tools.<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup><sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup><sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup><sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup></p>
<p>SIGNBT variants supported discovery, commands, file and process control, screenshots, and in-memory modules. COPPERHEDGE variants hid data in the registry or NTFS alternate data streams and used encrypted web traffic for control.<sup id="fnref1:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup><sup id="fnref1:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup></p>
<p>Operation Double Barrel found overlap between state-backed activity and Gunra ransomware in initial-access vulnerabilities, malware characteristics, SSH keys, and tunneling infrastructure. The English and Korean reports allowed for limited cooperation or shared resources but did not establish a firm relationship between the operators.<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup><sup id="fnref:15"><a href="#fn:15" class="footnote-ref" role="doc-noteref">15</a></sup></p>
<h3 id="5-a-fake-job-repository-led-to-the-afx-bridge-theft">5. A fake job repository led to the AFX bridge theft</h3>
<p>An early incident account described five compromised validator signatures authorizing a fraudulent withdrawal of about $24.15 million in USDC from the AFX bridge. The assets were moved to Ethereum, exchanged for ETH, and fragmented across many addresses. zeroShadow and SEAL assessed a highly likely link to <a href="https://lazarus.day/actors/unc4899/">UNC4899</a> from funding patterns, while describing the attribution as preliminary.<sup id="fnref:16"><a href="#fn:16" class="footnote-ref" role="doc-noteref">16</a></sup></p>
<p>AFX&rsquo;s later post-mortem attributed the theft to <a href="https://lazarus.day/actors/unc4899/">UNC4899</a> / <a href="https://lazarus.day/actors/tradertraitor/">TraderTraitor</a>. A developer cloned a malicious DEX repository offered through a fake job approach, triggering a modified Git post-checkout hook. The attacker persisted in JFrog through a malicious Groovy plugin and modified system components, recovered credentials, reached validator infrastructure through an operations bastion, and obtained the signatures needed for the unauthorized transaction. AFX found no compromise of Arbitrum or its native bridge.<sup id="fnref:17"><a href="#fn:17" class="footnote-ref" role="doc-noteref">17</a></sup></p>
<h3 id="6-it-worker-warnings-moved-from-revenue-to-insider-access">6. IT worker warnings moved from revenue to insider access</h3>
<p>A South Korean joint alert warned that DPRK IT workers use forged identities, third-country facilitators, laptop farms, VPNs, and remote desktop tools to obtain jobs and conceal their location.<sup id="fnref:18"><a href="#fn:18" class="footnote-ref" role="doc-noteref">18</a></sup> A parallel international alert added that facilitators may attend interviews, supply payment accounts, and operate remote machines. Both treated data theft, cryptocurrency theft, and access to sensitive systems as risks alongside salary diversion.<sup id="fnref:19"><a href="#fn:19" class="footnote-ref" role="doc-noteref">19</a></sup></p>
<p>Other reporting described AI as an aid to identity fraud, lure preparation, and analysis rather than an autonomous attack capability.<sup id="fnref:20"><a href="#fn:20" class="footnote-ref" role="doc-noteref">20</a></sup> A broader <a href="https://lazarus.day/actors/lazarus/">Lazarus</a> overview traced cryptocurrency theft through attacks on employees, signing authority, wallet providers, and development environments, followed by swaps, wallet fragmentation, chain hopping, and mixers.<sup id="fnref:21"><a href="#fn:21" class="footnote-ref" role="doc-noteref">21</a></sup></p>
<p>Hato Tsusin was assessed as part of a DPRK-linked commercial network procuring RF, navigation, sensor, and communications components.<sup id="fnref:22"><a href="#fn:22" class="footnote-ref" role="doc-noteref">22</a></sup> A newly surfaced SiliVaccine version had replaced the Trend Micro engine found in an older sample with ClamAV signatures and Malheur-based clustering.<sup id="fnref:23"><a href="#fn:23" class="footnote-ref" role="doc-noteref">23</a></sup></p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Development teams should inspect code that runs on package import as well as install hooks. After removing an affected package, rebuild compromised environments and rotate developer, cloud, and cryptocurrency credentials. Treat repositories delivered through recruitment contacts as untrusted even when the project appears functional.</p>
<p>South Korean website operators should monitor site integrity and patch third-party client security components. Hiring teams should compare identity, access location, payment ownership, video behavior, remote-control software, and account-use patterns before granting internal access.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://opensourcemalware.com/blog/polinrider-caused-dozens-of-npm-and-go-compromises">PolinRider Caused Dozens of npm and Go Compromises</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://safedep.io/joyfill-npm-blockchain-c2-supply-chain">Joyfill npm Packages Compromised with Blockchain C2 Loader</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a>&#160;<a href="#fnref1:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise">Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a>&#160;<a href="#fnref1:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://socket.dev/blog/joyfill-npm-beta-releases-compromised">Two Joyfill npm Beta Releases Compromised to Deliver DEV#POPPER Remote Access Trojan</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a>&#160;<a href="#fnref1:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://aws.amazon.com/blogs/security/amazon-identifies-north-korean-hacker-group-behind-open-source-supply-chain-attacks">Amazon identifies North Korean hacker group behind open-source supply chain attacks</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/mitigation-guidance-for-supply-chain-compromise">Batten Down Your Packages: Mitigation Guidance for Supply Chain Compromise</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://www.allsecure.io/blog/clickfix-etherhiding-dprk-wallet">ClickFix, EtherHiding &amp; a DPRK Wallet Trail</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://opensourcemalware.com/blog/nullreceiver-dprk-c2-technique">NullReceiver&rsquo;s Blank Crypto Transfers Solves the Challenges of EtherHiding</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://main.whoisxmlapi.com/threat-reports/apt37-strikes-again-this-time-with-narwhalrat">APT37 Strikes Again, This Time with NarwhalRAT</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://plainbit.co.kr/kr/insight/tech_hub?bgu=view&amp;idx=72">워터링홀 사고 사례</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://s2w.medium.com/detailed-analysis-of-signbt-malware-cluster-504fc3ab4ecf">Detailed Analysis of SIGNBT Malware Cluster</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a>&#160;<a href="#fnref1:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://krcert.or.kr/kr/bbs/view.do?bbsId=B0000133&amp;pageIndex=1&amp;nttId=72144&amp;menuNo=205020">국가배후 해킹조직의 우리 국민·기업 해킹 공격 주의 권고</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://www.enki.co.kr/media-center/blog/joint-cybersecurity-advisory-watering-hole-malware-analysis">합동 사이버 보안 권고문 기술 분석 보고서(워터링홀 공격)</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a>&#160;<a href="#fnref1:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p><a href="https://asec.ahnlab.com/en/94696">Operation Double Barrel (The Relationship Between a State-Sponsored Threat Actor and the Gunra Ransomware Group)</a>&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:15">
<p><a href="https://asec.ahnlab.com/ko/94695">Operation Double Barrel (국가배후 해킹조직과 Gunra 랜섬웨어 그룹의 관계)</a>&#160;<a href="#fnref:15" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:16">
<p><a href="https://rekt.news/ko/afx-trade-rekt">AFX Trade</a>&#160;<a href="#fnref:16" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:17">
<p><a href="https://medium.com/@AFXTrade/a-detailed-post-mortem-on-the-afx-security-incident-57d564ef812f">A Detailed Post-Mortem on the AFX Security Incident</a>&#160;<a href="#fnref:17" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:18">
<p><a href="https://www.mofa.go.kr/www/brd/m_4080/view.do?seq=377471&amp;page=1&amp;pitem=10">북한 IT 인력 관련 공동주의보 발표</a>&#160;<a href="#fnref:18" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:19">
<p><a href="https://www.ic3.gov/CSA/2026/260731.pdf">Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers</a>&#160;<a href="#fnref:19" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:20">
<p><a href="https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/2026-h1-apt-report-how-apts-are-weaponizing-trust-in-the-age-of-ai">2026 H1 APT Report: How APTs Are Weaponizing Trust in the Age of AI</a>&#160;<a href="#fnref:20" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:21">
<p><a href="https://ascencriptonewsletter.substack.com/p/grupo-lazarus-analise-completa-dos">Grupo Lazarus: Análise Completa dos hackers da Coreia do Norte</a>&#160;<a href="#fnref:21" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:22">
<p><a href="https://nkinternet.com/2026/07/28/hato-tsusin-a-long-forgotten-dprk-front-company-hiding-in-plain-sight">Hato Tsusin: A Long-Forgotten DPRK Front Company Hiding in Plain Sight?</a>&#160;<a href="#fnref:22" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:23">
<p><a href="https://nkinternet.com/2026/08/01/a-new-silivaccine-north-koreas-antivirus">A New SiliVaccine: North Korea’s Antivirus</a>&#160;<a href="#fnref:23" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW30: ClickFix meetings, groupware compromise, and IT worker revenue</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w30/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w30/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Fake meetings and job interviews drove several DPRK-linked operations last week. <a href="https://lazarus.day/actors/bluenoroff/">BlueNoroff</a>, <a href="https://lazarus.day/actors/sapphiresleet/">Sapphire Sleet</a>, and <a href="https://lazarus.day/actors/famouschollima/">Famous Chollima</a> used compromised contacts or recruiter personas to direct targets to imitation meeting pages, then persuaded Windows and macOS users to execute commands. The resulting malware targeted browser credentials, cryptocurrency wallets, and remote control of the host.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Fake meetings and job interviews drove several DPRK-linked operations last week. <a href="https://lazarus.day/actors/bluenoroff/">BlueNoroff</a>, <a href="https://lazarus.day/actors/sapphiresleet/">Sapphire Sleet</a>, and <a href="https://lazarus.day/actors/famouschollima/">Famous Chollima</a> used compromised contacts or recruiter personas to direct targets to imitation meeting pages, then persuaded Windows and macOS users to execute commands. The resulting malware targeted browser credentials, cryptocurrency wallets, and remote control of the host.</p>
<p><a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> reporting covered compromise at a South Korean groupware developer and movement into customer environments. Related presentations added victim counts and contrasted spearphishing with watering-hole exploitation. IT worker reporting followed both the hiring risk and the flow of salaries into a centralized state-linked payment system. An initial AFX account documented a bridge theft through developer compromise without making the later, more specific attribution published the following week.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-fake-meetings-turned-trusted-conversations-into-execution">1. Fake meetings turned trusted conversations into execution</h3>
<p>JUMPSEC documented a <a href="https://lazarus.day/actors/bluenoroff/">BlueNoroff</a> platform that used stolen Telegram accounts to approach cryptocurrency targets, profile their browsers, relay webcam feeds, and present fake Zoom or Teams meetings. Windows targets received a VBScript implant identified as NukeSped, while the macOS chain used a fake installer to conceal a Mach-O stealer.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup><sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<p>The ORO intrusion also began with a compromised Telegram contact and a fake Teams meeting. After an employee ran AppleScript, the attacker installed a browser extension and persistent implant, then stole the wallet controlling Bittensor SN15 and sold 147,000 Alpha Tokens. ORO attributed the operation to <a href="https://lazarus.day/actors/sapphiresleet/">Sapphire Sleet</a> from infrastructure and payload overlap with Microsoft reporting.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
<p><a href="https://lazarus.day/actors/famouschollima/">Famous Chollima</a> used fake cryptocurrency and Web3 interviews to deliver PylangGhost on Windows and GolangGhost plus a SwiftUI credential stealer on macOS. Invitation gating, browser fingerprinting, countdown pressure, and camera-error prompts increased pressure while limiting casual inspection.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<h3 id="2-groupware-compromise-reached-downstream-customers">2. Groupware compromise reached downstream customers</h3>
<p>ENKI reported that <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> exploited a mail-server vulnerability at a South Korean groupware developer and likely used spearphishing in some cases. The attackers stole internal data and credentials, modified a login page to capture customer credentials, and deployed BirdTroy and DriveTroy. The Go-based backdoors used HTTP/3 and Google Drive for command and control.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup><sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup></p>
<p>A conference presentation on the same activity added that at least four customers were compromised through one vendor&rsquo;s product and five more victim servers were identified through infrastructure tracking. It also documented Gomir, HttpTroy, HelloDoor, reverse proxying, and movement into deployment and development systems.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<h3 id="3-lnk-files-and-watering-holes-covered-different-access-paths">3. LNK files and watering holes covered different access paths</h3>
<p><a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> lures impersonating diplomatic personnel used malicious LNK files to install PebbleDash and PrxClient, create persistence, and relay traffic to RDP.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup> AhnLab&rsquo;s English and Korean June reviews documented broader work-themed LNK and spearphishing chains using PowerShell, AutoIt, HTA, scheduled tasks, DLL side-loading, and Python.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup><sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup> A game-character design lure followed a similar shortcut-to-script pattern and ended with MoonPeak, a XenoRAT-based implant.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup></p>
<p>A separate presentation contrasted targeted spearphishing with watering holes that exploit vulnerable South Korean Non-ActiveX security software. The demonstrated chains used public cloud and code-hosting services during delivery and control, then performed discovery, anti-analysis checks, in-memory execution, and remote command handling.<sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup></p>
<h3 id="4-it-worker-operations-combined-access-and-revenue">4. IT worker operations combined access and revenue</h3>
<p>Remote workers used stolen or fabricated identities, AI-generated application material, manipulated video, and laptop farms to enter Western companies. Reported outcomes included malware installation after onboarding, source-code theft, extortion, and possible supply-chain access.<sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup></p>
<p>Records from an exposed DPRK payment server contained 390 accounts, chats, and cryptocurrency transactions. Workers sent salary payments through luckyguys.site to an administrator account, after which funds were pooled through structures associated with Unit 1020, Command 710, and a wallet assessed as likely tied to sanctioned Korea Ryonbong General Corporation.<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup></p>
<h3 id="5-cryptocurrency-theft-and-naming-changes-needed-careful-context">5. Cryptocurrency theft and naming changes needed careful context</h3>
<p>AFX&rsquo;s first incident account said a malicious repository shared over Telegram compromised a developer, after which the attacker persisted in JFrog and moved toward validator infrastructure. A remote payload enabled unauthorized access to the custody bridge. The report said neither Arbitrum nor its native bridge was compromised and did not yet make the <a href="https://lazarus.day/actors/unc4899/">UNC4899</a> attribution that appeared in the following week&rsquo;s detailed post-mortem.<sup id="fnref:15"><a href="#fn:15" class="footnote-ref" role="doc-noteref">15</a></sup></p>
<p>Daily NK&rsquo;s account of former military intelligence personnel stealing from North Korean banks described domestic crime using state-developed skills, not a state-directed external operation.<sup id="fnref:16"><a href="#fn:16" class="footnote-ref" role="doc-noteref">16</a></sup> Google also announced that DPRK-attributed clusters would use <a href="https://lazarus.day/actors/neptune/">NEPTUNE</a> as the second word in its unified naming system, while retaining old names and aliases for search.<sup id="fnref:17"><a href="#fn:17" class="footnote-ref" role="doc-noteref">17</a></sup></p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Block meeting or interview workflows that instruct users to run Terminal, PowerShell, or AppleScript commands. Verify unexpected requests through a separate channel even when they come from a known account. Groupware operators should review mail-server exposure, login-page integrity, vendor access, and unusual use of Google Drive or tunneling services from servers.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.jumpsec.com/guides/inside-a-dprk-bluenoroff-clickfix-kit">Inside a DPRK BlueNoroff ClickFix Kit</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://www.jumpsec.com/bluenoroff-clickfix-kit-threat-investigation-report/">BlueNoroff ClickFix Kit Threat Investigation Report</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://x.com/oroagents/status/2079371018880041257">ORO Hack Post-Mortem: The Sapphire Sleet Intrusion</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://socradar.io/blog/dprk-clickfake-pylangghost-golangghost-rats/">DPRK’s Famous Chollima Deploys RATs Through ClickFake Job Interviews</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://www.enki.co.kr/en/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant">Analysis of Kimsuky&rsquo;s Attack on a South Korean Groupware Vendor Using a New Gomir Family Variant</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://www.enki.co.kr/media-center/blog/analysis-of-kimsuky-s-attack-on-a-south-korean-groupware-vendor-using-a-new-gomir-family-variant">신종 Gomir Family를 이용한 Kimsuky의 국내 그룹웨어 개발사 공격 분석</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://github.com/Plainbit/Slides/blob/main/2026%20%EC%83%81%EB%B0%98%EA%B8%B0%20%EC%B9%A8%ED%95%B4%EC%82%AC%EA%B3%A0%20%EC%A0%95%EB%B3%B4%EA%B3%B5%EC%9C%A0%20%EC%84%B8%EB%AF%B8%EB%82%98/08-%EA%B5%AD%EB%82%B4%20%EA%B7%B8%EB%A3%B9%EC%9B%A8%EC%96%B4%20%EB%8C%80%EC%83%81%20%EB%B6%81%ED%95%9C%20APT%20%EA%B3%B5%EA%B2%A9%20%EB%B6%84%EC%84%9D_%EA%B9%80%EC%98%81%EC%9A%B4(%EC%97%94%ED%82%A4).pdf">국내 그룹웨어 대상 북한 APT 공격 분석</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://asec.ahnlab.com/ko/94553/">Kimsuky 그룹의 외교 관련 종사자 사칭 공격 사례 (PebbleDash, PrxClient)</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://asec.ahnlab.com/en/94594">June 2026 Threat Trend Report on APT Attacks (South Korea)</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://asec.ahnlab.com/ko/94593">2026년 6월 APT 공격 동향 보고서(국내)</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://hauri.co.kr/security/security_view.html?intSeq=90">게임 업계 대상 MoonPeak 감염 사례 분석</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://github.com/Plainbit/Slides/blob/main/2026%20%EC%83%81%EB%B0%98%EA%B8%B0%20%EC%B9%A8%ED%95%B4%EC%82%AC%EA%B3%A0%20%EC%A0%95%EB%B3%B4%EA%B3%B5%EC%9C%A0%20%EC%84%B8%EB%AF%B8%EB%82%98/04-%EA%B5%AD%EB%82%B4%20%EC%97%94%EB%93%9C%ED%8F%AC%EC%9D%B8%ED%8A%B8%20%EB%8C%80%EC%83%81%20%EA%B3%B5%EA%B2%A9%EC%9D%98%20%EB%91%90%20%EC%B6%95%2C%20%EC%8A%A4%ED%94%BC%EC%96%B4%ED%94%BC%EC%8B%B1%EA%B3%BC%20%EC%9B%8C%ED%84%B0%EB%A7%81%20%ED%99%80_%EC%9D%B4%EC%84%A0%ED%98%B8(%EC%95%88%EB%9E%A9).pdf">국내 엔드포인트 대상 공격의 두 축, 스피어피싱과 워터링 홀</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://blog.opsek.io/north-korean-it-workers-remote-hiring/">North Korean IT Workers: How DPRK infiltrates remote hiring</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p><a href="https://www.dtex.ai/blog/dprk-it-worker-money-trail">From Payroll to Pyongyang: The DPRK IT Worker Money Trail</a>&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:15">
<p><a href="https://medium.com/@AFXTrade/afx-bridge-incident-what-happened-what-we-learned-and-what-comes-next-d97387746012">AFX Bridge Incident: What Happened, What We Learned, and What Comes Next</a>&#160;<a href="#fnref:15" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:16">
<p><a href="https://www.dailynk.com/english/north-korea-elite-bank-hacking-ring-arrested/">North Korea busts elite hacking ring inside its own banks</a>&#160;<a href="#fnref:16" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:17">
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/updated-cyber-threat-actor-naming-system/">Updated Cyber Threat Actor Naming System</a>&#160;<a href="#fnref:17" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW29: Developer access, package spread, and IT worker infrastructure</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w29/</link><pubDate>Mon, 20 Jul 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w29/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting joined two risks that often begin with developer access. Fake coding tests delivered cross-platform credential theft, while stolen developer accounts and package publishing access spread malicious code through GitHub and npm. <a href="https://lazarus.day/actors/polinrider/">PolinRider</a>&rsquo;s confirmed footprint rose to 4,367 repositories, and separate research connected the ChainVeil and ViteVenom package clusters to the same campaign with differing attribution confidence.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting joined two risks that often begin with developer access. Fake coding tests delivered cross-platform credential theft, while stolen developer accounts and package publishing access spread malicious code through GitHub and npm. <a href="https://lazarus.day/actors/polinrider/">PolinRider</a>&rsquo;s confirmed footprint rose to 4,367 repositories, and separate research connected the ChainVeil and ViteVenom package clusters to the same campaign with differing attribution confidence.</p>
<p>Remote employment created another path into software companies. Consensys disclosed that a consultant later linked to North Korea worked on MetaMask code for about a month, while infrastructure research mapped VPN routes, internal systems, and team-specific networks used by DPRK IT workers. <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> spearphishing and separate Windows and Android surveillance tools rounded out the week.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-recruitment-put-developer-credentials-and-code-at-risk">1. Recruitment put developer credentials and code at risk</h3>
<p>Elastic&rsquo;s <a href="https://lazarus.day/actors/ref9403/">REF9403</a> campaign used fake recruitment and trojanized coding assignments. Payload fragments hidden in SVG flag images were reconstructed when the project ran, launching an OTTERCOOKIE-aligned JavaScript implant on Windows, macOS, and Linux. It stole browser and wallet data, collected files, monitored the clipboard, and accepted Socket.IO commands.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p><a href="https://lazarus.day/actors/polinrider/">PolinRider</a> then demonstrated what stolen developer access can enable at scale. Researchers identified 2,417 additional compromised repositories in July, bringing the confirmed total to 4,367 repositories across 2,152 owners. Configuration injection accounted for 93.9 percent of the new cases, and more than 90 percent of affected owners were individual developers.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<h3 id="2-package-clusters-shared-infrastructure-but-attribution-differed">2. Package clusters shared infrastructure, but attribution differed</h3>
<p>Checkmarx found seven Vite-themed npm packages linked to ChainVeil through TRON and Aptos wallets, XOR keys, loader design, and payload behavior. It assessed a common operator but did not connect that operator to North Korea.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup> OpenSourceMalware later attributed ChainVeil and ViteVenom to the DPRK-linked <a href="https://lazarus.day/actors/polinrider/">PolinRider</a> campaign, citing blockchain indicators it had published before the packages appeared, along with campaign markers and targeting patterns.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<p>The combined reporting supports a common technical cluster more strongly than it supports every attribution claim equally. Defenders can act on the shared wallets, keys, loader structure, and package behavior without collapsing those confidence differences.</p>
<h3 id="3-it-workers-reached-trusted-development-environments">3. IT workers reached trusted development environments</h3>
<p>Consensys said a consultant using the alias &ldquo;Tyler Knapp&rdquo; was later identified through its investigation as connected to North Korea. The consultant contributed to core and mobile MetaMask code, including crypto-to-fiat functionality, for roughly one month. Consensys suspended releases and said it found no malicious code, stolen assets or data, or user impact.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup></p>
<p>Stealer-log analysis separately mapped infrastructure used by DPRK fake IT workers. The records indicated routes through Russian exit nodes and VPN endpoints in the United States and Japan, linked internal networks to the Second Economy Committee, Ryonbong, and Kim Chaek University of Technology, and exposed several operational teams. A newly observed cluster labeled PUG remained unresolved.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup></p>
<h3 id="4-spearphishing-and-surveillance-remained-active">4. Spearphishing and surveillance remained active</h3>
<p><a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> impersonated diplomatic personnel and sent malicious LNK attachments with diplomatic decoys. The chains installed PebbleDash and PrxClient, added persistence and keylogging tools, and could relay command traffic to local RDP. ASEC said recent activity targeted people in the education sector.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<p>A suspected <a href="https://lazarus.day/actors/apt-c-26/">APT-C-26</a>, or <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>, operation added the <code>KKernel.exe</code> keylogger to an existing remote-desktop surveillance platform. The service spawned an agent in the active user session, recorded keystrokes with foreground process context, and transmitted new logs every 30 seconds.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup> S2W attributed BirdCall, a repackaged Zangi messenger, to <a href="https://lazarus.day/actors/scarcruft/">ScarCruft</a>. The Android spyware used Zoho WorkDrive for tasking and exfiltration and collected device data, contacts, calls, messages, directories, and files. Screenshot, microphone, and keylogging code was present but inactive in the sample.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Run coding tests from unknown recruiters in disposable environments without browser sessions, wallets, or production tokens. Review SVG files, package import behavior, and configuration changes as executable risk. Software companies should verify remote workers throughout employment, not only at onboarding, and restrict new contractors from release systems until identity and access patterns are established.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.elastic.co/security-labs/contagious-interview-malware-svg-steganography">New North Korean campaign uses fake coding interviews to steal developer credentials</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://opensourcemalware.com/blog/polinrider-blast-radius-grows">PolinRider Confirmed Footprint Grows 6.5x Since March</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://checkmarx.com/zero-post/sequel-to-chainveil-npm-malware-targets-vite-ecosystem/">Sequel to ChainVeil npm malware: ViteVenom</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://opensourcemalware.com/blog/chainveil-and-vitevenom-dprk-polinrider-campaign">ChainVeil and ViteVenom are DPRK’s PolinRider Campaign</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://www.dropsitenews.com/p/consensys-metamask-crypto-wallet-hired-north-korean-hacker">Major Blockchain Firm Consensys Accidentally Hired a North Korean Hacker</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://kudelskisecurity.com/research/dprk-fake-it-workers-inside-their-evolving-network-infrastructure">DPRK Fake IT Workers: Inside Their Evolving Network Infrastructure</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://asec.ahnlab.com/en/94552/">Attack Cases by the Kimsuky Group Impersonating Diplomats (PebbleDash, PrxClient)</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://mp.weixin.qq.com/s/6hjjsEuuOTk8_FJrXWe9Ew">疑似APT-C-26（Lazarus）组织升级监控程序的攻击行动分析</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://s2w.medium.com/detailed-analysis-of-birdcall-malware-marsqurading-as-zangi-messenger-b80db8f5c320">Detailed Analysis of BirdCall Malware: Masquerading as Zangi Messenger</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW28: PolinRider expansion, cross-chain laundering, and RokRAT delivery</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w28/</link><pubDate>Mon, 13 Jul 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w28/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting covered developer ecosystem compromise, digital-asset theft and laundering, and an <a href="https://lazarus.day/actors/apt37/">APT37</a> RokRAT campaign. <a href="https://lazarus.day/actors/polinrider/">PolinRider</a> expanded from npm into Go modules, Packagist packages, and Chrome extensions. The reporting tied that expansion to compromised GitHub accounts and repository release paths, putting source-control identity at the center of package security.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting covered developer ecosystem compromise, digital-asset theft and laundering, and an <a href="https://lazarus.day/actors/apt37/">APT37</a> RokRAT campaign. <a href="https://lazarus.day/actors/polinrider/">PolinRider</a> expanded from npm into Go modules, Packagist packages, and Chrome extensions. The reporting tied that expansion to compromised GitHub accounts and repository release paths, putting source-control identity at the center of package security.</p>
<p>Cross-chain bridges and DeFi infrastructure appeared as both compromise points and laundering routes. A separate <a href="https://lazarus.day/actors/apt37/">APT37</a> investigation traced spearphishing that impersonated a real academic conference, disguised a loader as a PDF, and used public cloud services for RokRAT command and control.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-polinrider-crossed-package-ecosystems">1. PolinRider crossed package ecosystems</h3>
<p>OpenSourceMalware reported almost 200 malicious release artifacts tied to 111 packages and extensions, including more than 80 Go modules and 10 Packagist packages. Because those ecosystems can publish directly from repositories and tags, a stolen GitHub account can become package-registry access. The campaign hid JavaScript in configuration files and fake <code>.woff2</code> files, used VS Code folder-open tasks, and delivered BeaverTail, InvisibleFerret, OtterCookie, or OmniStealer.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p>CYFIRMA likewise assessed that <a href="https://lazarus.day/actors/famouschollima/">Famous Chollima</a> was expanding <a href="https://lazarus.day/actors/polinrider/">PolinRider</a> beyond npm into Go modules, Packagist, and Chrome extensions. It described compromised repositories and maintainer accounts as paths to developer credentials, browser data, and wallet information, while labeling its associated YARA rule low confidence.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<h3 id="2-an-npm-backdoor-delayed-execution">2. An npm backdoor delayed execution</h3>
<p><code>nodemon-sudo</code> version 3.1.16 copied the legitimate nodemon package but added <code>tslint-conf</code>, a repackaged logger containing a backdoor. The code did not run at installation or import. It waited until the fake logger middleware was called, then spawned a detached Node process, fetched JavaScript through a Pinata IPFS gateway, and executed it with access to <code>require</code>.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
<p>SafeDep linked the package pair to earlier <code>nodemon-node</code> and <code>ts-await</code> activity through reused code and infrastructure. It also noted resemblance to a North Korea-linked npm cluster but said the attribution was based on technique and remained unconfirmed. This distinction matters because delayed execution and IPFS retrieval are useful detection leads, not proof of actor identity.</p>
<h3 id="3-cross-chain-systems-joined-intrusion-and-laundering">3. Cross-chain systems joined intrusion and laundering</h3>
<p>SlowMist described <a href="https://lazarus.day/actors/lazarus/">Lazarus</a> activity as a sequence spanning supply-chain compromise, social engineering, DeFi attacks, cross-chain infrastructure abuse, and laundering. Privacy protocols, bridges, lending platforms, and mixers created layered movement that made tracing harder. Its broader review recorded 182 blockchain incidents and about USD 956 million in first-half losses, with supply-chain attacks causing the largest losses by value.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<p>The Financial Security Institute estimated that <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>-linked or suspected activity accounted for about 63 percent of the cross-chain hacking losses it reviewed. Its cases included Ronin Bridge, Harmony Horizon, Orbit Chain, and KelpDAO, with failures involving social engineering, endpoints, validator keys, and RPC infrastructure. Reported laundering methods included decentralized exchanges, Tornado Cash, Railgun, Wasabi CoinJoin, chain hopping, wallet splitting, exchanges, and OTC networks.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup></p>
<h3 id="4-apt37-delivered-rokrat-through-a-conference-lure">4. APT37 delivered RokRAT through a conference lure</h3>
<p>Genian&rsquo;s Korean and English reports assessed that Operation Capsule Vault likely began with a spearphishing email impersonating a real academic conference. An ISO image contained a PIF loader disguised as a PDF. The loader opened a legitimate decoy, decoded shellcode, and injected an x64 RokRAT variant into <code>explorer.exe</code>.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup><sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<p>RokRAT collected host and document data, executed commands, and captured screenshots. It used pCloud, Dropbox, and Yandex for command and control. Reused Yandex credentials, infrastructure, implementation details, and code similarity to Operation Artemis supported the <a href="https://lazarus.day/actors/apt37/">APT37</a> attribution.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Protect GitHub maintainer accounts and release tags with the same care as package-registry credentials. Monitor changes to <code>tasks.json</code>, font files containing script code, unfamiliar transitive dependencies, and Node processes that retrieve code from IPFS or blockchain services.</p>
<p>For document lures, connect ISO mounting, PIF execution, decoy display, process injection, and unusual cloud-service traffic. Cross-chain defenses should separately protect signer endpoints, validator independence, administrative changes, RPC infrastructure, and fund-movement monitoring.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://opensourcemalware.com/blog/polinrider-jumps-the-fence">PolinRider Jumps the Fence</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://www.cyfirma.com/news/weekly-intelligence-report-10-jul-2026">Weekly Intelligence Report – 10 Jul 2026</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://safedep.io/malicious-nodemon-sudo-tslint-conf-npm-backdoor/">nodemon-sudo: an npm Backdoor With No Install Script</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://slowmist.medium.com/slowmist-2026-mid-year-blockchain-security-and-aml-report-75e0862179ef">2026 Mid-year Blockchain Security and AML Report</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://www.fsec.or.kr/bbs/detail?menuNo=244&amp;bbsNo=11990">디지털자산 크로스 체인 보안 위협 분석</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://www.genians.co.kr/blog/threat_intelligence/rokrat_capsule_vault">Operation Capsule Vault: EMBED_PAYLOAD_v2 기반 RokRAT 공격 체인 분석</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://www.genians.co.kr/en/blog/threat_intelligence/rokrat_capsule_vault">Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW27: Contagious Interview infrastructure, IT worker personas, and crypto laundering</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w27/</link><pubDate>Mon, 06 Jul 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w27/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting expanded the visible scale of DPRK access operations around developers. Ossprey mapped hundreds of <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> payload URLs and a separate Node.js RAT cluster. Other researchers documented malicious open-source packages, trojanized interview projects, compromised maintainer accounts, and GitHub personas apparently built to support fraudulent employment.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting expanded the visible scale of DPRK access operations around developers. Ossprey mapped hundreds of <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> payload URLs and a separate Node.js RAT cluster. Other researchers documented malicious open-source packages, trojanized interview projects, compromised maintainer accounts, and GitHub personas apparently built to support fraudulent employment.</p>
<p>Cryptocurrency reporting focused on scale and post-theft movement. TRM attributed about two thirds of first-half losses to North Korea-linked activity, while S2W traced repeated use of mixers, bridges, swaps, exchanges, and OTC networks. <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> reporting continued to favor LNK and CHM lures backed by public cloud and code-hosting services.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-contagious-interview-exposed-a-large-mutable-payload-network">1. Contagious Interview exposed a large, mutable payload network</h3>
<p>Ossprey identified 298 active payload URLs after malicious npm packages led researchers into a JSONkeeper dead-drop namespace. The operation delivered BeaverTail against browser, password-manager, and cryptocurrency-wallet data. A separate 36-sample Node.js RAT cluster used port 1244 with a <code>ZT3</code> handshake, and researchers mapped 26 C2 servers. A live <code>buffer-util-internal</code> package showed that operators could rotate payloads during the investigation.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p>JFrog found Rollup-themed npm lookalikes that retrieved JSONKeeper content and launched Node.js components for remote access, browser and wallet theft, file collection, and clipboard monitoring.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup> Kudelski Security documented the social path into similar tooling: recruiters contacted developers through LinkedIn, WhatsApp, Discord, and CodeMentor, then pressured them to run trojanized projects. One fake Ajuna Network repository used <code>npm install</code> and a hidden VS Code task to start a backdoor and steal <code>process.env</code> secrets.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
<h3 id="2-polinrider-crossed-package-ecosystems-and-repository-boundaries">2. PolinRider crossed package ecosystems and repository boundaries</h3>
<p>Socket identified 162 malicious release artifacts across 108 packages and extensions linked to <a href="https://lazarus.day/actors/polinrider/">PolinRider</a>, including 80 Go modules and 10 Packagist packages. Some cases involved compromised maintainer accounts and rewritten Git history. Loaders hid in configuration files or fake <code>.woff2</code> files, ran through VS Code tasks, and resolved later stages through blockchain or RPC infrastructure.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<p>The affected assets extended beyond package-registry credentials. A compromised developer workstation could expose GitHub, npm, cloud, SSH, browser, and wallet secrets, then provide a route into source repositories and CI systems. This makes repository identity and release history part of the incident scope, not merely the package that first triggered detection.</p>
<h3 id="3-github-personas-supported-fraudulent-employment-access">3. GitHub personas supported fraudulent employment access</h3>
<p>NorthScan identified <code>fullstackdev0110</code>, <code>reo0603</code>, and <code>buddy0323</code> as a coordinated GitHub persona cluster with indicators consistent with DPRK IT worker activity. One persona reused an Indian developer&rsquo;s portfolio, another person&rsquo;s photograph, and contradictory identity and location data. Repeated, ordered references across unrelated historical issues suggested a shared or scripted method for manufacturing contribution history.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup></p>
<p>The cluster also overlapped with proxy-interview infrastructure tied to the <code>ghost</code>, <code>NeymaFullStack</code>, and <code>7codewizard</code> personas. The finding connects source-control reputation building with the same hiring channel that intrusion operators exploit through fake recruiter contact, although IT worker fraud and malware delivery remain distinct operational paths.</p>
<h3 id="4-cryptocurrency-losses-concentrated-in-infrastructure-compromise">4. Cryptocurrency losses concentrated in infrastructure compromise</h3>
<p>TRM recorded 207 cryptocurrency hacks and USD 972 million in losses during the first half of 2026. It attributed about USD 643 million, or 66 percent, to North Korea-linked activity, driven largely by the Drift Protocol and KelpDAO incidents. The largest losses came from keys, credentials, signing systems, and custody workflows rather than smart-contract exploits.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup></p>
<p>S2W traced laundering after publicly attributed thefts involving Ronin Bridge, Horizon Bridge, Atomic Wallet, DMM Bitcoin, and Bybit. Funds moved through wallet splitting, mixers, bridges, cross-chain swaps, exchange services, OTC networks, and stablecoin conversion. THORChain, eXch, Chinese Laundromat-style brokers, and Huione-related services appeared as recurring infrastructure or settlement paths.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<h3 id="5-gaslight-targeted-both-macos-data-and-ai-assisted-analysis">5. Gaslight targeted both macOS data and AI-assisted analysis</h3>
<p>Moonlock&rsquo;s coverage of Gaslight described a Rust-based macOS stealer and backdoor linked to North Korean operators. It collected browser data, Terminal history, process and application lists, system profiles, and the encrypted login keychain, then used Telegram for tasking and exfiltration. The sample also embedded 38 fake system messages intended to mislead AI-assisted triage.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup></p>
<p>Moonlock noted that this sample did not aggressively target wallets directly, even though its likely delivery context overlapped with prior DPRK targeting of developers, Web3 organizations, gaming companies, and fake job or meeting lures. Analysis systems should isolate untrusted sample content from model instructions.</p>
<h3 id="6-kimsuky-document-lures-performed-staged-reconnaissance">6. Kimsuky document lures performed staged reconnaissance</h3>
<p>AhnLab&rsquo;s Korean and English monthly reports described South Korea-focused spearphishing dominated by LNK and CHM files. The chains used PowerShell, VBScript, HTA, Python, scheduled tasks, DLL side-loading, and legitimate Windows utilities to stage backdoors and infostealers.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup><sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup></p>
<p>Synaptic Systems analyzed a CHM lure that launched hidden PowerShell, decoded a VBScript bootstrap, profiled the host with WMI, uploaded folder and process inventories, and created an hourly scheduled task. The final payload appeared selective and was not returned during controlled replay.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup> Hauri documented a military-journal-themed LNK that used Dropbox and GitHub for VBE, batch, and PowerShell stages before collecting system details, download-directory listings, and process data.<sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup></p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Run external coding assignments in disposable environments without production credentials. Record VS Code task and package-script execution, and audit repository history if a suspicious package or project ran. Credential rotation should cover source control, cloud accounts, SSH keys, registries, browser sessions, and wallets.</p>
<p>For <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> detection, connect CHM or LNK execution with script interpreters, scheduled tasks, decoy documents, and traffic to public cloud or code-hosting services. A missing final payload does not make the reconnaissance chain benign.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.ossprey.com/blog/how-ossprey-uncovered-a-large-scale-dprk-contagious-interview-campaign">How Ossprey uncovered a 300+ package DPRK Contagious-Interview campaign</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://research.jfrog.com/post/rollup-polyfill-masquerading/">Lazarus-Linked npm Malware Masquerades as Rollup Polyfills</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://kudelskisecurity.com/research/how-dprks-contagious-interview-campaign-targets-developers">How DPRK’s Contagious Interview Campaign Targets Developers</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://socket.dev/blog/polinrider-north-korea-linked-supply-chain-campaign-expands">PolinRider: North Korea-Linked Supply Chain Campaign Expands Across Open Source Ecosystems</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://northscan.co/articles/github-diaries">The GitHub Diaries of DPRK IT Workers</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://www.trmlabs.com/resources/blog/h1-2026-crypto-hacks-reach-record-high-as-losses-fall-below-usd-1-billion">H1 2026 Crypto Hacks Reach Record High as Losses Fall Below USD 1 Billion</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://s2w.inc/ko/resource/detail/1090">북한 배후 조직의 자금세탁 인프라 및 네트워크 분석</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://moonlock.com/gaslight-malware-evades-ai-analysis">New Gaslight malware uses prompt injection to evade AI analysis</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://asec.ahnlab.com/ko/94270/">2026년 5월 APT 공격 동향 보고서(국내)</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://asec.ahnlab.com/en/94271/">May 2026 Threat Trend Report on APT Attacks (South Korea)</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://blog.synapticsystems.de/inside-kimsukys-chm-tradecraft-multi-stage-execution-and-selective-payload-delivery/">Inside Kimsuky’s CHM Tradecraft: Multi-Stage Execution and Selective Payload Delivery</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://hauri.co.kr/security/security_view.html?intSeq=89">군사·안보 학술지로 위장한 Kimsuky 정찰용 악성코드</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW26: Managed IT worker operations, macOS intrusion, and blockchain dead drops</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w26/</link><pubDate>Mon, 29 Jun 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w26/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting covered several routes into developer and financial environments. Internal records obtained by the BBC described a managed DPRK IT worker operation built around borrowed identities, assigned roles, close supervision, and foreign-currency quotas. Malware research documented memory-resident Windows tooling, macOS surveillance implants, malicious npm packages, and <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> phishing chains.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting covered several routes into developer and financial environments. Internal records obtained by the BBC described a managed DPRK IT worker operation built around borrowed identities, assigned roles, close supervision, and foreign-currency quotas. Malware research documented memory-resident Windows tooling, macOS surveillance implants, malicious npm packages, and <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> phishing chains.</p>
<p>The developer supply-chain reporting also moved beyond individual package names. Researchers described blockchain transactions as mutable dead drops for payload infrastructure, while a review of the Mastra compromise detailed how one npm account exposed 144 packages. Across these cases, the sensitive assets were often developer credentials, browser sessions, wallet data, signing access, and source code.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-it-worker-fraud-operated-as-a-managed-organization">1. IT worker fraud operated as a managed organization</h3>
<p>BBC Korea obtained recordings and internal messages describing security managers, task managers, support staff who prepared resumes and accounts, and workers who applied for remote jobs under borrowed or stolen identities. Operators recruited identity lenders through social and dating services, managed several accounts and devices, and followed rules on email, time zones, and interview language to hide their location.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup></p>
<p>A former worker described shared workspaces, constant monitoring, monthly foreign-currency quotas, and little personal freedom. The records portray a structured revenue operation, not isolated freelance fraud. Hiring controls therefore need to verify identity, device custody, account sharing, work location, and payment ownership before granting source-code or cloud access.</p>
<h3 id="2-developer-supply-chains-used-packages-and-blockchain-dead-drops">2. Developer supply chains used packages and blockchain dead drops</h3>
<p>A review of the Mastra incident said <a href="https://lazarus.day/actors/sapphiresleet/">Sapphire Sleet</a> compromised the <code>ehindero</code> npm account and inserted <code>easy-day-js@1.11.22</code> into 144 packages during an 88-minute publishing window. The payload established cross-platform persistence and targeted browser extensions, tokens, secrets, and CI credentials.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<p>A separate <a href="https://lazarus.day/actors/polinrider/">PolinRider</a> teardown found loaders hidden in the functional npm packages <code>tailwind-color-shades</code> and <code>safe-validate</code>. They resolved encrypted stages through TRON, Aptos, and Binance Smart Chain transactions before contacting version-gated infrastructure and delivering BeaverTail or InvisibleFerret components.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup> OpenSourceMalware described malicious-version sandwiching, campaign markers such as <code>ace-a6-shadow-15</code>, and the reuse of blockchain infrastructure as research pivots. It also cautioned that similar supply-chain techniques are spreading beyond DPRK operators.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup></p>
<p><a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> reporting added <code>chalk-ultra</code> and <code>vitest-cli</code>. The packages downloaded tooling that stole source code, browser data, developer credentials, and wallet information, and could replace MetaMask with a persistent trojanized extension. Ossprey linked the activity to the campaign through distribution and payload overlap but kept attribution of the specific packages unconfirmed.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup></p>
<h3 id="3-macos-intrusion-mixed-user-execution-surveillance-and-analysis-evasion">3. macOS intrusion mixed user execution, surveillance, and analysis evasion</h3>
<p>SentinelLABS assessed Gaslight as DPRK-aligned macOS activity with high confidence. The Rust implant used Telegram for command and control, created LaunchAgent persistence, provided an interactive shell, and ran a Python stealer against browser data, shell history, process information, system profiles, and the login keychain. Its binary also contained 38 fake system messages intended to derail LLM-assisted malware analysis.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup></p>
<p>Another RAT masqueraded as MicrosoftSystem64 and bundled JavaScript inside a Mach-O binary. It supported screenshots, keylogging, clipboard monitoring, shell commands, file operations, and theft from browsers, secret files, and more than 50 wallet types. It used WebSocket traffic for tasking and an operator-controlled Hugging Face dataset for bulk exfiltration.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<p>Darktrace observed ClickFix-style macOS social engineering followed by AppleScript or other native scripting and sustained outbound signaling. It tied the use case to activity Microsoft linked to DPRK but assigned only moderate confidence based on behavioral overlap.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup> The evidence supports behavioral detection of user-driven script execution and rare outbound control channels without treating every similar chain as confirmed DPRK activity.</p>
<h3 id="4-financial-targeting-favored-memory-resident-access">4. Financial targeting favored memory-resident access</h3>
<p>Cognyte analyzed DPAPILoader, RemotePELoader, and an in-memory RemotePE RAT used against financial institutions and cryptocurrency organizations. Windows DPAPI provided environmental keying, which made payload recovery and analysis harder away from the victim system. RemotePE supported command execution, file handling, process control, and host-data access.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<p>CYFIRMA&rsquo;s quarterly review placed that tooling in a broader mix of cryptocurrency theft, supply-chain compromise, cloud intrusion, and espionage. It described <a href="https://lazarus.day/actors/lazarus/">Lazarus</a> targeting exchanges, DeFi platforms, software vendors, defense contractors, and technology companies, while <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> and <a href="https://lazarus.day/actors/andariel/">Andariel</a> retained distinct intelligence and sector priorities.<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup></p>
<h3 id="5-kimsuky-kept-document-lures-but-changed-supporting-infrastructure">5. Kimsuky kept document lures but changed supporting infrastructure</h3>
<p>IIJ-SECT observed a KimJongRAT chain that redirected shortened email links to GitHub Releases containing LNK payloads. The chain used <code>mshta</code>, obfuscated VBScript, Google Drive-hosted encrypted payloads, and different execution paths depending on Windows Defender. Newer samples fetched encrypted C2 configuration at runtime and included experimental MeshAgent installation as a fallback access path.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup></p>
<p>An emulation of <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a>&rsquo;s DEEP#DRIVE initial access reproduced an LNK that launched hidden PowerShell, downloaded staged files, opened a decoy PDF, and created scheduled-task persistence. The useful telemetry included <code>explorer.exe</code> spawning PowerShell and an unusual PowerShell-to-PDF-reader lineage. The post clearly separated its proof-of-concept downloads from campaign indicators.<sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup></p>
<h3 id="6-embassy-wireless-observations-remained-contextual">6. Embassy wireless observations remained contextual</h3>
<p>Passive collection outside the DPRK embassy in London exposed ISP history, remembered SSIDs, printers, a television, a router, Sonos equipment, and a likely Sky Q device. The researcher said the collection occurred from public space without connecting to or authenticating with a network.<sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup> These observations are physical-location OSINT, not evidence of a cyber campaign.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Monitor developer systems for package execution that reaches blockchain RPC services, JSON dead drops, or uncommon Node.js control channels. If a suspicious package ran, rotate repository, cloud, browser, wallet, and CI credentials from a clean host.</p>
<p>On macOS, connect social-engineering prompts with AppleScript, LaunchAgent creation, keychain access, and unusual Telegram, WebSocket, or Hugging Face traffic. Malware-analysis pipelines should treat extracted strings as hostile data rather than model instructions.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.bbc.com/korean/articles/clyx7gkyjr1o">북한 IT 위장 취업조직의 실체…BBC가 입수한 북한 내부 기록을 열어보니</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://www.decryptiondigest.com/blog/sapphire-sleet-mastra-npm-supply-chain-attack">Sapphire Sleet: 144 npm Packages Backdoored</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://meltedinhex.com/posts/polinrider-blockchain-dead-drop-npm/">Dead Drops on the Blockchain: Reversing a DPRK npm Loader (PolinRider / A6-Shadow-15)</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://opensourcemalware.com/blog/opensourcemalware-show-episode10">The OpenSourceMalware Show #10</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://www.ossprey.com/blog/dprk-contagious-interview-npmjs-chalk-ultra-and-vitest-cli">DPRK Contagious Interview: NPMJS chalk-ultra and vitest-cli</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/">macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://archive.md/NAcCm">New macOS (crossplatform) sample</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://www.darktrace.com/blog/from-click-to-command-behavioral-detection-of-applescript-led-macos-intrusions">From Click to Command: Behavioral Detection of AppleScript-Led MacOS Intrusions</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://www.cognyte.com/blog/lazarus-targets-the-financial-sector-with-memory-only-malware-toolset/">Lazarus Targets the Financial Sector with Memory-Only Malware Toolset</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://www.cyfirma.com/research/apt-quarterly-report-apr-to-jun-2026/">APT QUARTERLY REPORT : APR TO JUN 2026</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://sect.iij.ad.jp/blog/2026/06/continuous-evolution-of-kimjongrat-2026/">LOTSを活用して進化を続けるKimJongRAT</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://0x00sec.org/emulating-kimsukys-initial-access/">Emulating Kimsuky&rsquo;s Initial Access</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://nkinternet.com/2026/06/23/gunnersbury-avenue-sniffing-the-dprk-embassys-wifi/">Gunnersbury Avenue: Sniffing the DPRK Embassy’s WiFi</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW25: Mastra npm compromise, developer lures, and crypto custody failures</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w25/</link><pubDate>Mon, 22 Jun 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w25/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting centered on developer access as a route into software supply chains and cryptocurrency systems. The Mastra incident put that risk into production at scale: a compromised maintainer account added <code>easy-day-js</code> to more than 140 npm packages, exposing developer workstations and CI runners to a cross-platform Node.js implant. Other reports described malicious code hidden in configuration files, blockchain-based payload resolution, fake interviews, and poisoned packages.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting centered on developer access as a route into software supply chains and cryptocurrency systems. The Mastra incident put that risk into production at scale: a compromised maintainer account added <code>easy-day-js</code> to more than 140 npm packages, exposing developer workstations and CI runners to a cross-platform Node.js implant. Other reports described malicious code hidden in configuration files, blockchain-based payload resolution, fake interviews, and poisoned packages.</p>
<p>The same access problem appeared in cryptocurrency custody. Reporting on Humanity Protocol and Bybit traced major losses to compromised workstations, exposed signing material, cloud sessions, and manipulated interfaces rather than broken cryptography. DPRK IT worker investigations showed a parallel path into companies through stolen identities, laptop farms, and fraudulent hiring.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-one-maintainer-account-exposed-the-mastra-release-chain">1. One maintainer account exposed the Mastra release chain</h3>
<p>Microsoft attributed the Mastra compromise to <a href="https://lazarus.day/actors/sapphiresleet/">Sapphire Sleet</a> with high confidence. The actor took over the dormant <code>ehindero</code> npm account and inserted <code>easy-day-js</code> into more than 140 <code>mastra</code> and <code>@mastra</code> packages. Mastra said the takeover followed social phishing through a compromised LinkedIn account.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup><sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<p>The malicious dependency ran during installation, disabled TLS validation, downloaded a second Node.js stage, detached it from the install process, and removed the dropper. Researchers documented Windows, macOS, and Linux persistence, browser and wallet reconnaissance, remote tasking, and possible exposure of developer and CI credentials.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup><sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup><sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup><sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup> OpenSourceMalware found close overlap with the Axios npm compromise but kept attribution unconfirmed, as did TuxCare and Snyk.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup><sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup><sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<h3 id="2-developer-files-packages-and-interviews-all-became-execution-paths">2. Developer files, packages, and interviews all became execution paths</h3>
<p>A developer found obfuscated JavaScript in <code>tailwind.config.js</code> and another backend file across several repositories. The code reportedly used TRON JSON-RPC with an Aptos fallback to resolve later infrastructure. The author linked the activity to <a href="https://lazarus.day/actors/voiddokkaebi/">Void Dokkaebi</a>, while noting that initial access was still unknown.<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup> Checkmarx described similar blockchain-backed resolution in ChainVeil, a campaign attributed to an actor it calls <a href="https://lazarus.day/actors/successkey/">SuccessKey</a>. Its npm loaders used TRON, Aptos, and Binance Smart Chain transactions before delivering a remote-access trojan.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup></p>
<p>AhnLab&rsquo;s monthly reports placed these techniques in a wider DPRK-linked pattern involving malicious Git hooks, Jenkins workflows, npm and Packagist branches, Cloudflare Workers, and blockchain RPC services.<sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup><sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup> ESRC tied the <code>chai-as-init</code> npm package to <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> after it stole environment variables and executed remote JavaScript from Vercel-hosted infrastructure.<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup></p>
<p>Recruitment supplied the social pretext. One LinkedIn lure sent a developer to a GitHub project whose npm <code>prepare</code> script launched a backdoor.<sup id="fnref:15"><a href="#fn:15" class="footnote-ref" role="doc-noteref">15</a></sup> A separate discussion of fake interviews described how plausible recruiter contact, broken calls, shared repositories, login prompts, and screen sharing can gradually move a target toward execution or credential disclosure.<sup id="fnref:16"><a href="#fn:16" class="footnote-ref" role="doc-noteref">16</a></sup></p>
<h3 id="3-endpoint-access-defeated-cryptocurrency-custody-controls">3. Endpoint access defeated cryptocurrency custody controls</h3>
<p>A Humanity Protocol director reportedly opened a spearphishing email impersonating Bithumb. Malware on the director&rsquo;s Windows laptop exposed MetaMask data and enough production keys to cross multisignature thresholds. The attacker then changed ProxyAdmin ownership, drained bridge assets, and enabled unauthorized token minting.<sup id="fnref:17"><a href="#fn:17" class="footnote-ref" role="doc-noteref">17</a></sup><sup id="fnref:18"><a href="#fn:18" class="footnote-ref" role="doc-noteref">18</a></sup></p>
<p>Bybit reporting traced the February 2025 theft to a compromised Safe{Wallet} developer workstation, stolen cloud sessions, AWS access, and injected frontend JavaScript that showed signers legitimate transaction details while changing the underlying action. Sygnia said the operation aligned with <a href="https://lazarus.day/actors/lazarus/">Lazarus</a> tradecraft.<sup id="fnref:19"><a href="#fn:19" class="footnote-ref" role="doc-noteref">19</a></sup> Bybit&rsquo;s later complaint attributed the theft to <a href="https://lazarus.day/actors/lazarus/">Lazarus</a> acting for North Korea&rsquo;s Reconnaissance General Bureau and said only about $75.5 million of the roughly $1.5 billion theft had been frozen or recovered by the filing date.<sup id="fnref:20"><a href="#fn:20" class="footnote-ref" role="doc-noteref">20</a></sup> A broader <a href="https://lazarus.day/actors/lazarus/">Lazarus</a> overview placed these cases beside fake recruitment, poisoned packages, IT worker infiltration, and laundering through cross-chain services.<sup id="fnref:21"><a href="#fn:21" class="footnote-ref" role="doc-noteref">21</a></sup></p>
<h3 id="4-document-shortcuts-kept-script-heavy-intrusion-chains-active">4. Document shortcuts kept script-heavy intrusion chains active</h3>
<p>AhnLab analyzed LNK files disguised as a consent form and a resume. The consent-form chain opened a decoy while PowerShell created downloaders, scheduled-task persistence, host discovery, and an in-memory backdoor loader.<sup id="fnref:22"><a href="#fn:22" class="footnote-ref" role="doc-noteref">22</a></sup> The resume lure created batch, PowerShell, and VBScript files, registered recurring execution, downloaded later components with <code>curl</code>, and used DLL side-loading to run Xctdoor.<sup id="fnref:23"><a href="#fn:23" class="footnote-ref" role="doc-noteref">23</a></sup></p>
<p>The information-stealing flow resembled earlier <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> activity, but the reports focused on the observed execution chains rather than making a broad new attribution. The practical detection point is the process lineage from an apparent business document into script interpreters, scheduled tasks, and side-loaded DLLs.</p>
<h3 id="5-it-worker-operations-scaled-identity-and-access-fraud">5. IT worker operations scaled identity and access fraud</h3>
<p>Nisos identified more than 170,000 applications to US companies over ten months, producing 76 offers for 22 operatives. The operation used appropriated identities, forged documents, AI-assisted interviews, US laptop farms, PiKVM devices, Tailscale, VPNs, and cryptocurrency payments.<sup id="fnref:24"><a href="#fn:24" class="footnote-ref" role="doc-noteref">24</a></sup></p>
<p>Balkan Insight reported stolen identities from Bosnia and Serbia on freelance platforms, along with overseas facilitators and payment services.<sup id="fnref:25"><a href="#fn:25" class="footnote-ref" role="doc-noteref">25</a></sup> Together, the cases show why hiring controls need to verify the person, device, location, remote access path, and payment owner before repository or cloud access is granted.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Organizations that installed affected Mastra releases should investigate the workstation or runner where installation occurred. Review lifecycle-script execution, outbound Node.js traffic, persistence, browser and wallet access, and exposure of CI secrets. Rotate credentials from a clean system and rebuild affected environments.</p>
<p>Run unfamiliar coding tests in isolated environments without production credentials. Cryptocurrency organizations should separate privileged keys across independently controlled systems, add timelocks to administrative changes, and verify the transaction actually signed rather than relying only on the displayed interface.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.microsoft.com/en-us/security/blog/2026/06/17/postinstall-payload-inside-mastra-npm-supply-chain-compromise/">From package to postinstall payload: Inside the Mastra npm supply chain compromise by Sapphire Sleet</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://github.com/mastra-ai/mastra/issues/18061">INCIDENT REPORT: 2026-06-16: Mastra hit by supply-chain attack</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://socket.dev/blog/mastra-npm-packages-compromised">140+ Mastra npm Packages Compromised in Coordinated Supply Chain Attack</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://research.jfrog.com/post/easy-day-js/">easy-day-js: Supply Chain Campaign Targets Mastra npm Packages</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://safedep.io/mastra-npm-scope-takeover-supply-chain-attack/">Mastra npm Scope Takeover: 143 Packages Drop a RAT</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://www.stepsecurity.io/blog/mastra-npm-packages-compromised-using-easy-day-js">Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://opensourcemalware.com/blog/mastra-npm-malware">Mastra Attack Targets Crypto, Password Managers, Authenticators, and Zapier</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://tuxcare.com/blog/mastra-npm-attack/">Why the Mastra easy-day-js Attack Should Change How Teams Trust npm Packages</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/">A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://infosecwriteups.com/i-found-north-korean-dprk-malware-hiding-in-my-tailwind-config-js-45af2283742c">I found a malware hiding in my tailwindcss config file</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://checkmarx.com/zero-post/chainveil-a-malicious-npm-supply-chain-attack-by-successkey/">ChainVeil: A Malicious npm Supply Chain Attack by SuccessKey</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://asec.ahnlab.com/ko/94144/">2026년 5월 APT 그룹 동향 보고서</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://asec.ahnlab.com/en/94145/">May 2026 Threat Trend Report on APT Groups</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p><a href="https://blog.alyac.co.kr/5766">Chai.js 플러그인으로 위장한 북한발 npm 악성 패키지 &lsquo;chai-as-init&rsquo; 분석</a>&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:15">
<p><a href="https://roman.pt/posts/linkedin-backdoor/">A backdoor in a LinkedIn job offer</a>&#160;<a href="#fnref:15" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:16">
<p><a href="https://open.spotify.com/episode/4NVfhji063MWdYYqZakKag">The Day It Became Access: How Fake Interviews Turn Developer Trust Into Attack Surface</a>&#160;<a href="#fnref:16" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:17">
<p><a href="https://rekt.news/humanity-protocol-rekt">Humanity Protocol</a>&#160;<a href="#fnref:17" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:18">
<p><a href="https://www.quillaudits.com/blog/hack-analysis/humanity-protocol-admin-key-compromise">Humanity Protocol $36M Admin Key Compromise Exploit (Explained)</a>&#160;<a href="#fnref:18" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:19">
<p><a href="https://www.sygnia.co/case-study/bybit-heist-case-study/">Bybit Heist Case Study: When Billions Vanish</a>&#160;<a href="#fnref:19" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:20">
<p><a href="https://storage.courtlistener.com/recap/gov.uscourts.dcd.293673/gov.uscourts.dcd.293673.1.0.pdf">Bybit vs DPRK</a>&#160;<a href="#fnref:20" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:21">
<p><a href="https://www.blackfog.com/lazarus-group-what-businesses-need-to-know/">Lazarus Group Cyber Attacks: What Businesses Need To Know</a>&#160;<a href="#fnref:21" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:22">
<p><a href="https://asec.ahnlab.com/ko/94162/">개인정보 동의서인 줄 알았던 바로가기 파일의 정체는?</a>&#160;<a href="#fnref:22" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:23">
<p><a href="https://asec.ahnlab.com/ko/94163/">정상 이력서처럼 보이지만 실행 순간 감염 시작</a>&#160;<a href="#fnref:23" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:24">
<p><a href="https://nisos.com/research/dprk-employment-fraud-operation/">Exposing DPRK Employment Fraud Operations</a>&#160;<a href="#fnref:24" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:25">
<p><a href="https://balkaninsight.com/2026/06/15/why-me-north-korean-hackers-steal-identities-from-serbia-bosnia/bi/">‘Why Me?’: North Korean Hackers Steal Identities From Serbia, Bosnia</a>&#160;<a href="#fnref:25" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW24: Signer theft, malicious pull requests, and phishing RATs</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w24/</link><pubDate>Mon, 15 Jun 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w24/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>The Humanity Protocol <code>$H</code> compromise was the clearest incident last week. A phishing attachment led to remote access on a director&rsquo;s Windows endpoint, theft of wallet and signer material, changes to bridge and contract authority, unauthorized minting, and token sales. The incident joined endpoint security directly to protocol governance and market impact.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>The Humanity Protocol <code>$H</code> compromise was the clearest incident last week. A phishing attachment led to remote access on a director&rsquo;s Windows endpoint, theft of wallet and signer material, changes to bridge and contract authority, unauthorized minting, and token sales. The incident joined endpoint security directly to protocol governance and market impact.</p>
<p>Developer-focused reporting covered malicious pull requests, build configuration, fake repositories, browser trust, and IT worker infiltration. <a href="https://lazarus.day/actors/apt37/">APT37</a> and <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> retained more traditional spear-phishing chains built around LNK files, scripts, cloud services, and remote control. A claimed sale of DPRK-linked data remained unverified and belongs outside the core evidence set.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-one-phished-endpoint-exposed-protocol-authority">1. One phished endpoint exposed protocol authority</h3>
<p>Humanity&rsquo;s investigation said a Bithumb-themed phishing attachment installed a signed loader and remote-access tooling on a director&rsquo;s Windows machine. Stolen MetaMask and private-key material was then used to alter contract control, mint or move <code>$H</code>, drain operational wallets, and sell tokens.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup> Quantstamp linked the loader and supporting tooling to methods characteristic of DPRK intrusions.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<p>The incident update separated the affected Ethereum and BSC controls, including stolen Safe owner keys, ProxyAdmin takeover, a malicious bridge implementation, and unauthorized minting.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup> The result was not simply wallet loss. Endpoint access reached bridge administration, mint authority, liquidity, and market price.</p>
<h3 id="2-pull-requests-and-editor-tasks-carried-supply-chain-risk">2. Pull requests and editor tasks carried supply chain risk</h3>
<p>A malicious pull request hid an obfuscated loader in <code>astro.config.mjs</code>, where normal Astro build or preview commands executed it. SafeDep linked the payload to <a href="https://lazarus.day/actors/polinrider/">PolinRider</a> through matching cryptographic and blockchain dead-drop artifacts.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup> A broader campaign review traced DPRK-linked activity across npm, PyPI, Go, Cargo, Packagist, TasksJacker repository compromises, and later malicious pull requests using stolen credentials.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup></p>
<p>Proofpoint&rsquo;s <a href="https://lazarus.day/actors/unk_deaddrop/">UNK_DeadDrop</a> cluster sent more than 250 developer-phishing emails and used GitHub or GitLab repositories, VS Code or Cursor tasks, malicious extensions, and Overlord-derived RATs to steal wallets and credentials.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup> Google Docs research linked fake developer interview tasks with IT worker recruitment adverts through shared images and revision metadata.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<h3 id="3-browser-and-employee-trust-remained-valuable-access-layers">3. Browser and employee trust remained valuable access layers</h3>
<p>An episode on the Google Mirror described infrastructure designed to proxy Google services around a DPRK-linked developer campaign. It did not claim that Google or a certificate authority was compromised, but it identified browser identity, mail, OAuth, account recovery, cloud drives, and source-control recovery as follow-on targets.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup></p>
<p>Corelight described fraudulent IT workers using stolen or synthetic identities, laptop farms, and remote-management tooling to enter organizations with valid credentials and trusted devices.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup> CrowdStrike&rsquo;s technology-sector review likewise placed <a href="https://lazarus.day/actors/famouschollima/">FAMOUS CHOLLIMA</a> employment fraud beside supply chain activity by other DPRK clusters.<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup> These are identity and access problems as much as malware problems.</p>
<h3 id="4-apt37-and-kimsuky-kept-tailored-phishing-chains-active">4. APT37 and Kimsuky kept tailored phishing chains active</h3>
<p>Genians published Korean and English reports on <a href="https://lazarus.day/actors/apt37/">APT37</a>&rsquo;s NarwhalRAT campaign. Microsoft-themed phishing delivered an LNK, scripts, an embedded Python runtime, and in-memory malware with keylogging, screen and microphone capture, USB staging, file transfer, and pCloud-based dead-drop resolution.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup><sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup></p>
<p>A <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> campaign targeted a South Korean information-security team with a personal-data leak inquiry, built trust over several emails, and resent the payload in a password-protected archive after blocking. The resulting chains used Dropbox or direct HTTPS C2, scheduled tasks, startup VBS, anti-analysis, and self-deletion.<sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup></p>
<h3 id="5-marketplace-claims-remained-unverified">5. Marketplace claims remained unverified</h3>
<p>DEVIL MARLBORO advertised an alleged 419 GB package containing DPRK-linked tooling, certificates, operator data, wallets, and facility information.<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup> The public report verified the offer, not the authenticity, freshness, or provenance of its contents. Until independent evidence emerges, the sale is a collection lead rather than proof of a breach or tool leak.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Blockchain projects should treat signer endpoints, Safe ownership, ProxyAdmin control, timelocks, bridge upgrades, and emergency response as one security boundary. Developer teams should review pull requests and editor automation before execution, while identity teams correlate remote employees, device location, KVM use, OAuth recovery, and unusual source-control access.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.humanity.org/hincidentupdate">Investigation Summary</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://x.com/Humanityprot/status/2065480523057647652">$H Incident: Tooling Linked to North Korean Actors</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://humanityprotocol.notion.site/H-Token-Incident-Update-37ab0ec467a781d7af06e7dcedd66852">H Token Incident Update</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://safedep.io/astro-config-blockchain-c2-supply-chain">astro.config.mjs Supply Chain Attack via Blockchain C2</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://opensourcemalware.com/blog/active-campaigns-jan-may-2026">Active Malware Campaigns in January-May 2026</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal">Don&rsquo;t Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://kmsec.uk/blog/dprk-google-docs/">Hunting North Korea&rsquo;s job adverts on Google Docs</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://open.spotify.com/episode/5wHFZWoiFyqA4Ejp9TljGi">The Google Mirror: Browser Trust as the Attack Surface</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://corelight.com/blog/north-korean-it-worker-insider-threat">The North Korean IT worker threat: A modern insider risk</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-technology-threat-landscape-report/">CrowdStrike 2026 Report: China Fuels Attacks on Tech</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://www.genians.co.kr/blog/threat_intelligence/narwhalrat">MS 사칭 피싱과 Dead-drop C2 기반 APT37 NarwhalRAT 분석</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://www.genians.co.kr/en/blog/threat_intelligence/narwhalrat">Analysis of APT37 NarwhalRAT Leveraging MS-Themed Phishing and Dead-drop C2</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://blog.alyac.co.kr/5761">개인정보 유출 의심 문의로 위장한 Kimsuky 스피어피싱 사례 분석</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p><a href="https://iqblack.com/insight/devil-marlboro-offers-for-sale-an-alleged/">DEVIL MARLBORO offers for sale an alleged intelligence package linked to Kimsuky and Lazarus Group</a>&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW23: npm brandjacking, in-memory control, and crypto laundering</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w23/</link><pubDate>Mon, 08 Jun 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w23/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting concentrated on developer supply chains and the financial operations around cryptocurrency theft. <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>-linked npm brandjacking and <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> activity targeted routine dependency installation and developer workstations, while new analysis of Copperhedge described the path from server exploitation to in-memory control.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reporting concentrated on developer supply chains and the financial operations around cryptocurrency theft. <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>-linked npm brandjacking and <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> activity targeted routine dependency installation and developer workstations, while new analysis of Copperhedge described the path from server exploitation to in-memory control.</p>
<p>KelpDAO reporting followed stolen funds across chains and mixers, while <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> infrastructure research expanded one domain into a broad cluster. Two other reports sat at the edge of the DPRK picture: Endpoint/Midnight ransomware had only a historical account overlap, and an AnySign4PC remediation notice described a vulnerability relevant to earlier exploitation reporting without attributing the flaw or all abuse to DPRK actors.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-supply-chain-access-remained-a-developer-problem">1. Supply chain access remained a developer problem</h3>
<p>Sonatype attributed dozens of npm packages using brandjacked or ecosystem-adjacent names to <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>. One package mixed legitimate Buffer code with a loader that fetched and evaluated follow-on JavaScript.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup> A broader review found <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> publishing across npm and PyPI and noted that malicious-package growth was not confined to one ecosystem.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<p>An OtterCookie episode focused on what happens after execution on a real developer machine: screenshots, keyboard and clipboard capture, browser history, authenticated sessions, wallets, cloud consoles, and source-control access.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup> The operational value lies in the trusted sessions surrounding the code, not simply in infecting a test host.</p>
<h3 id="2-exploitation-led-to-in-memory-lazarus-control">2. Exploitation led to in-memory Lazarus control</h3>
<p>Analysis attributed to <a href="https://lazarus.day/actors/apt-c-26/">APT-C-26</a> described bulk exploitation of CVE-2025-55182 followed by MultiRelay, Akagi64, and a Copperhedge loader that decrypted its backdoor in memory.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup> Copperhedge supported host discovery, command execution, file transfer, process control, timestamp changes, configuration updates, and reflective payload loading.</p>
<p>That chain links internet-facing exploitation with internal movement and a flexible backdoor. Detection should connect scanning and exploit attempts to UAC bypass, unusual <code>rundll32</code> execution, encrypted configuration storage, and memory-resident payload behavior.</p>
<h3 id="3-theft-and-laundering-extended-beyond-the-initial-transaction">3. Theft and laundering extended beyond the initial transaction</h3>
<p>A review of <a href="https://lazarus.day/actors/lazarus/">Lazarus</a> financial operations used the Bybit compromise to explain signer-interface manipulation, rapid swaps, bridge use, fund fragmentation, and later cash-out paths.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup> After the KelpDAO theft, reporting said the exploiter moved funds through Bitcoin, Wasabi, Ethereum, and Tornado Cash, leaving little in the tagged wallet while some assets remained frozen.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup></p>
<p>The KelpDAO article reports the project&rsquo;s attribution and recovery account, but post-theft movement alone is not an attribution test. It is most useful for monitoring bridge exits, cross-chain conversions, mixers, dormant wallets, and recovery constraints.</p>
<h3 id="4-kimsuky-infrastructure-scaled-through-repeated-fingerprints">4. Kimsuky infrastructure scaled through repeated fingerprints</h3>
<p>Infrastructure hunting expanded the seed domain <code>xpo.coupang.dns.navy</code> into 43 servers and 664 associated domains through hosting, service, HTML, and naming patterns.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup> The report assessed moderate-to-high confidence in the <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> link, but the larger pivot set still benefits from tiering by direct observation and corroboration.</p>
<h3 id="5-adjacent-reports-required-narrow-claims">5. Adjacent reports required narrow claims</h3>
<p>AhnLab&rsquo;s Endpoint/Midnight analysis described Babuk-derived ransomware for Windows, ESXi, and NAS systems, but its DPRK connection rested on a ransom-note email previously used by a North Korea-linked actor.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup> That is relevant overlap, not attribution of the full ransomware operation.</p>
<p>KISA&rsquo;s AnySign4PC notice advised removal or upgrade for vulnerable versions affected by a remotely exploitable buffer overflow.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup> It adds defensive context to reports of exploitation against Korean software, but the notice itself does not name a DPRK actor.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Review dependency installation and package publishing alongside endpoint sessions, cloud access, and source-control credentials. For cryptocurrency incidents, preserve signing telemetry and bridge records early enough to reconstruct both the access path and subsequent laundering. Keep infrastructure pivots and historical account overlaps in separate confidence tiers.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://www.sonatype.com/blog/lazarus-groups-latest-brandjacking-campaign-on-npm">Lazarus Group&rsquo;s Latest: Brandjacking Campaign on npm</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://opensourcemalware.com/blog/the-software-supply-chain-malware-landscape-january-may-2026">The Software Supply Chain Malware Landscape: January - May 2026</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://open.spotify.com/episode/3duLGBYbvsUD9y3gYSuNZR">OtterCookie: The Malware That Watched the Developer</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://mp.weixin.qq.com/s/3kwDMAXviaE1TUDnkYlqrg">APT-C-26（Lazarus）组织利用CVE-2025-55182与Copperhedge组件的攻击行动分析</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://medium.com/purefi/lazarus-group-the-hackers-with-a-national-budget-41f1878fc131">Lazarus Group: The Hackers With a National Budget</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://cointelegraph.com/news/kelp-dao-recovery-hacker-launders-most-funds-293m-exploit">Recovery hopes fade as Kelp DAO hacker launders nearly all $220M in stolen funds</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://idanmalihi.com/tracking-north-korea-nation-state-apt-infrastructure-kimsuky/">Tracking North Korea Nation-State APT Infrastructure: Kimsuky</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://asec.ahnlab.com/ko/93931/">새벽에 온 암호화 손님 Endpoint(Midnight) 랜섬웨어 분석</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://krcert.or.kr/kr/bbs/view.do?searchCnd=1&amp;bbsId=B0000133&amp;searchWrd=&amp;menuNo=205020&amp;pageIndex=6&amp;categoryCode=&amp;nttId=72074">보안인증 소프트웨어 취약점 관련 클리닝 서비스 가동 안내</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW22: Developer lures, stolen build access, and persistent control</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w22/</link><pubDate>Mon, 01 Jun 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w22/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reports kept developers and cryptocurrency organizations at the center of DPRK-linked activity. Fake recruiting, malicious editor tasks, compromised package branches, npm payloads, fake conferencing updates, and stolen development credentials all created paths from a single workstation into code distribution and financial systems.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Last week&rsquo;s reports kept developers and cryptocurrency organizations at the center of DPRK-linked activity. Fake recruiting, malicious editor tasks, compromised package branches, npm payloads, fake conferencing updates, and stolen development credentials all created paths from a single workstation into code distribution and financial systems.</p>
<p><a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> and <a href="https://lazarus.day/actors/ta406/">TA406</a> continued to pair tailored phishing with scripts, newly disclosed vulnerabilities, legitimate cloud services, and remote-access tooling. RemotePE supplied a separate model for long-lived access in finance, while broader reporting connected developer compromise to DeFi theft and supply chain operations. One infrastructure observation inside DPRK address space remained exploratory rather than a confirmed intrusion campaign.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-developer-lures-crossed-package-and-editor-boundaries">1. Developer lures crossed package and editor boundaries</h3>
<p>A smart-contract security developer received a fake recruiting email that led to a GitLab repository whose VS Code task installed a malicious extension and native Go implants.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup> A compromised Packagist development branch used a JavaScript loader and multi-blockchain dead drop in a likely <a href="https://lazarus.day/actors/famouschollima/">Famous Chollima</a> coding-task lure.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup> SafeDep&rsquo;s MicrosoftSystem64 analysis found a cross-platform npm RAT that stole browser, wallet, Telegram, SSH, clipboard, and screen data while using Hugging Face for exfiltration.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
<p><a href="https://lazarus.day/actors/sapphiresleet/">Sapphire Sleet</a> used a fake Zoom SDK update against macOS users in venture capital, Web3, and cryptocurrency organizations, followed by password prompts, TCC abuse, LaunchDaemon persistence, and an in-memory beacon.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup> Across these cases, ordinary developer and meeting workflows provided the execution path.</p>
<h3 id="2-stolen-development-access-enabled-downstream-compromise">2. Stolen development access enabled downstream compromise</h3>
<p>Wiz tracked <a href="https://lazarus.day/actors/jinx-0164/">JINX-0164</a> using recruiter lures and AUDIOFIX to steal wallet, cloud, GitHub, and CI/CD secrets before compromising software distribution and trojanizing <code>@velora-dex/sdk</code>.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup> A separate analysis described the same cluster as North Korea-linked, but the original Wiz assessment found behavioral similarities without infrastructure overlap and did not attribute it to a state sponsor.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup> The stronger conclusion is that <a href="https://lazarus.day/actors/jinx-0164/">JINX-0164</a> poses a directly relevant adjacent threat to the same cryptocurrency development environment.</p>
<p>RemotePE showed how <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>-linked access could persist after entry through memory-only execution, encrypted C2, plugin loading, and EDR evasion.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup> A monthly incident review placed these techniques beside the Drift Protocol and KelpDAO thefts and the Axios supply chain compromise.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup> ESET&rsquo;s multi-month review likewise covered the Axios intrusion, developer targeting, cryptocurrency operations, and activity by <a href="https://lazarus.day/actors/andariel/">Andariel</a> and <a href="https://lazarus.day/actors/scarcruft/">ScarCruft</a>.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<h3 id="3-kimsuky-and-ta406-reused-phishing-foundations-with-newer-components">3. Kimsuky and TA406 reused phishing foundations with newer components</h3>
<p>Proofpoint observed <a href="https://lazarus.day/actors/ta406/">TA406</a> chaining two Office and Windows vulnerabilities in diplomatic-themed RTF lures before retrieving and executing a DLL payload.<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup> ENKI published English and Korean analyses of <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> campaigns that used fake security software and Webex pages, JSONPing localhost checks, and a new in-memory HttpSpy variant.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup><sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup></p>
<p>A card-company secure-mail lure used LNK, PowerShell, mshta, obfuscated VBScript, Google Drive, and payloads for backdoor access and information theft.<sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup> AhnLab&rsquo;s April review placed similar LNK and script chains across South Korea-focused spear-phishing activity.<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup> Hauri&rsquo;s KimjongRAT variant added Telegram and Discord collection and installed a MeshCentral agent, shifting the chain toward persistent remote control.<sup id="fnref:15"><a href="#fn:15" class="footnote-ref" role="doc-noteref">15</a></sup></p>
<h3 id="4-infrastructure-labels-can-hide-wider-campaign-roles">4. Infrastructure labels can hide wider campaign roles</h3>
<p>An investigation of a server first labeled as FTP infrastructure later connected it to OtterCookie-related collection, a reminder that one observed service may reveal only part of a campaign host&rsquo;s purpose.<sup id="fnref:16"><a href="#fn:16" class="footnote-ref" role="doc-noteref">16</a></sup> Separately, NK Internet observed a captive portal framework under test in DPRK IP space, including connectivity checks, Korean comments, and a Huawei-themed WiFi error page.<sup id="fnref:17"><a href="#fn:17" class="footnote-ref" role="doc-noteref">17</a></sup></p>
<p>The captive portal finding supports monitoring, but it does not by itself establish a deployed phishing or access operation. Infrastructure purpose should be revised as new services and traffic become visible.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Treat repositories, package branches, editor tasks, conferencing updates, and development credentials as a connected attack surface. For <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> and <a href="https://lazarus.day/actors/ta406/">TA406</a> activity, correlate document and LNK delivery with localhost callbacks, script interpreters, cloud-hosted payloads, scheduled tasks, and newly installed remote-management agents.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://blog.denv.it/posts/i-was-likely-targeted-by-dprk-in-a-sophisticated-developer-malware-campaign/">I was likely targeted by DPRK in a sophisticated developer malware campaign</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://socket.dev/blog/famous-chollima-targets-php-developers-through-compromised-packagist-package">Famous Chollima Targets PHP Developers Through Compromised Packagist Package</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://safedep.io/microsoftsystem64-binary-payload-analysis/">Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://www.levelblue.com/blogs/spiderlabs-blog/sapphire-sleet-targets-macos-in-multi-stage-intrusion-campaign">Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://www.wiz.io/blog/threat-actors-target-crypto-orgs">Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry&rsquo;s Software Development Infrastructure</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://www.decryptiondigest.com/blog/jinx-0164-audiofix-cryptocurrency-macos-malware">JINX-0164 Cryptocurrency Malware: AUDIOFIX Wallet Theft (2026)</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://blog.polyswarm.io/lazarus-expands-financial-espionage-operations-with-memory-resident-remotepe-rat">Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://socradar.io/blog/april-2026-major-cyber-attacks/">April 2026: ShinyHunters Hits Medtronic and ADT as North Korean Hackers Drain DeFi Protocols</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://web-assets.esetstatic.com/wls/en/papers/threat-reports/eset-apt-activity-report-q4-2025-q1-2026.pdf">ESET APT Activity Report Q4 2025–Q1 2026</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://www.proofpoint.com/us/blog/threat-insight/more-cves-same-playbook-2026-vulnerability-exploitation-wild">More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://www.enki.co.kr/en/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant">Kimsuky&rsquo;s Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://www.enki.co.kr/media-center/blog/kimsuky-s-advanced-attack-techniques-jsonping-webex-spoofing-and-a-new-httpspy-variant">Kimsuky의 고도화된 공격 기법 분석: JSONPing, Webex 사칭, 그리고 새로운 HttpSpy 변종</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://asec.ahnlab.com/ko/93854/">‘보안 메일’도 안심 금물! 카드사 사칭 악성 파일 유포 중</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p><a href="https://asec.ahnlab.com/ko/93830/">2026년 4월 APT 공격 동향 보고서(국내)</a>&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:15">
<p><a href="https://hauri.co.kr/security/security_view.html?intSeq=88&amp;page=1&amp;keyfield=&amp;key=">KimjongRAT 변종: 정보 탈취에서 원격 접근 확보로의 확장</a>&#160;<a href="#fnref:15" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:16">
<p><a href="https://open.spotify.com/episode/5LLBPD3896kuyeHnc2FPxB">the FTP Server: How One Boring Label Hid a Second Layer of the Campaign</a>&#160;<a href="#fnref:16" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:17">
<p><a href="https://nkinternet.com/2026/05/26/dprk-captive-portal-infrastructure-found-in-testing/">DPRK Captive Portal Infrastructure Found in Testing</a>&#160;<a href="#fnref:17" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW21: Developer execution, in-memory access, and bridge compromise</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w21/</link><pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w21/</guid><description><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Developer compromise dominated last week&rsquo;s reporting. Fake interviews, poisoned repositories, npm install hooks, editor automation, compiled malware, and trojanized browser extensions all targeted workstations that already held source-control, cloud, package, and wallet credentials. New reporting on Axios-related infrastructure and packages widened that picture beyond a single compromise.</p>]]></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>Developer compromise dominated last week&rsquo;s reporting. Fake interviews, poisoned repositories, npm install hooks, editor automation, compiled malware, and trojanized browser extensions all targeted workstations that already held source-control, cloud, package, and wallet credentials. New reporting on Axios-related infrastructure and packages widened that picture beyond a single compromise.</p>
<p>RemotePE and the KelpDAO investigation showed the other end of the access chain: quiet persistence inside financial environments and manipulation of bridge verification infrastructure. Reporting on IT workers, sanctions, and operator forensics connected technical intrusion to identity fraud, laundering, and revenue generation, while two adjacent financial-sector reports required more cautious attribution.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-fake-interviews-turned-normal-developer-actions-into-execution">1. Fake interviews turned normal developer actions into execution</h3>
<p>A developer safety analysis described the core lure plainly: clone a repository, install dependencies, open it in an editor, or run a test on a workstation that already contains valuable credentials.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup> GitHub network analysis found <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> repositories abusing VS Code and Cursor configuration, git hooks, npm lifecycle scripts, and hidden JavaScript, with newer BeaverTail builds adding operator-directed WebSocket control.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup></p>
<p>Trend Micro found InvisibleFerret moving into Cython-compiled Windows and macOS modules, complicating script-focused detection while preserving browser, wallet, clipboard, and keylogging functions.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup> The progression from social engineering to compiled payloads and persistent control makes isolated repository review an incomplete defense.</p>
<h3 id="2-npm-and-browser-components-collected-developer-and-wallet-secrets">2. npm and browser components collected developer and wallet secrets</h3>
<p>A cross-platform Node.js stealer tied to an OtterCookie C2 targeted browser credentials, wallet data, private keys, tokens, SSH keys, and source code on Windows, macOS, and Linux.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup> OX Security found similar breadth in <code>terminal-logger-utils</code>, which used a postinstall hook, bundled Node executables, Hugging Face, and WebSocket remote control.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup></p>
<p>Three npm packages linked to the Axios attacker had collected developer, cloud, npm, SSH, Docker, browser, and git data for weeks.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup> OpenSourceMalware placed those packages within parallel <a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> and TasksJacker activity,<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup> while DNS analysis of the Axios operation mapped the confirmed WAVESHAPER.V2 infrastructure and separated it from unverified pivots.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup></p>
<p>The browser layer was also exposed. Five trojanized extensions masqueraded as password managers or wallets, resolved C2 through an Aptos transaction, and linked stolen wallet artifacts to browser identity data.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<h3 id="3-financial-intrusions-favored-durable-low-noise-access">3. Financial intrusions favored durable, low-noise access</h3>
<p>Fox-IT described RemotePE as an in-memory RAT delivered through victim-bound DPAPI decryption and a loader that unhooked DLLs, patched ETW, and resolved direct syscalls.<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup> The KelpDAO incident report then documented social engineering against a LayerZero developer, session-key theft, poisoned RPC nodes, monitoring evasion, and a single-verifier design that accepted the attacker&rsquo;s attestation.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup></p>
<p>Chainalysis connected DPRK IT worker proceeds and cyber theft to exchanges, bridges, DeFi services, and mixers used for sanctions evasion.<sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup> These reports join endpoint access, cloud sessions, bridge verification, and laundering into one defensive problem.</p>
<h3 id="4-it-worker-and-operator-evidence-exposed-the-human-infrastructure">4. IT worker and operator evidence exposed the human infrastructure</h3>
<p>A suspected <a href="https://lazarus.day/actors/chollima/">Chollima</a> applicant used a Colombian identity and a residential Bogota connection, possibly through local facilitation or a residential proxy, while showing behavior consistent with AI-assisted interviewing.<sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup> A forensic episode about a <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>-attributed operator disk described fake-company material, targeting pipelines, wallet artifacts, and browser traces from an eleven-hour preservation window.<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup></p>
<p>A broader campaign-linkage assessment argued that IT worker fraud, recruitment lures, cloud compromise, credential theft, and cryptocurrency operations share access and infrastructure.<sup id="fnref:15"><a href="#fn:15" class="footnote-ref" role="doc-noteref">15</a></sup> That assessment is useful as a model, but the incident-level evidence should still determine attribution in each case.</p>
<h3 id="5-financial-sector-overlap-did-not-always-establish-attribution">5. Financial-sector overlap did not always establish attribution</h3>
<p>AhnLab linked observed WGear exploitation and GeniexLoader installation to activity associated with <a href="https://lazarus.day/actors/andariel/">Andariel</a> and <a href="https://lazarus.day/actors/bluenoroff/">BlueNoroff</a>.<sup id="fnref:16"><a href="#fn:16" class="footnote-ref" role="doc-noteref">16</a></sup> Its Endpoint/Midnight ransomware analysis, however, found only that a historical ransom-note email had been used by a North Korea-linked actor; it did not attribute the ransomware family itself.<sup id="fnref:17"><a href="#fn:17" class="footnote-ref" role="doc-noteref">17</a></sup></p>
<p>Bridewell&rsquo;s annual report supplied broader context on identity compromise, trusted-platform abuse, supply chain attacks, and attacker use of AI.<sup id="fnref:18"><a href="#fn:18" class="footnote-ref" role="doc-noteref">18</a></sup> These trend-level and adjacent findings belong below directly attributed cases in analytic confidence.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Inspect interview repositories before they reach a normal workstation. Block automatic folder tasks and install hooks in untrusted projects, and review browser extensions, package tokens, SSH agents, cloud credentials, and wallet access after any suspected execution. In financial environments, correlate those endpoint signals with unusual RPC changes, session-key use, and verifier behavior.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://redasgard.com/blog/fake-coding-interview-developer-safety-checklist">A Fake Coding Interview Is an Execution Request: Developer Safety Checklist</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://archive.md/JMkiH">Deep Dive into Active Github Network Running Contagious Interview</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://www.trendmicro.com/en_us/research/26/e/analyzing-void-dokkaebi-invisibleferret-malware.html">Analyzing Void Dokkaebi’s Cython-Compiled InvisibleFerret Malware</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://dshield.org/diary/CrossPlatform+NPM+Stealer/33006/">Cross-Platform NPM Stealer</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://www.ox.security/blog/north-korean-npm-infostealer-rat/">North Korean-Linked Threat Actor Targets Developers with New npm Infostealer RAT</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://opensourcemalware.com/blog/axios-attacker-additional-npm-packages">Axios attacker strikes again! Three NPM packages have been hiding in plain sight for two months</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://opensourcemalware.com/blog/opensourcemalware-show-episode05">The OpenSourceMalware Show #5</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://main.whoisxmlapi.com/threat-reports/the-dns-anatomy-of-the-axios-supply-chain-attack">The DNS Anatomy of the Axios Supply Chain Attack</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://redasgard.com/blog/hunting-lazarus-part9-google-mirror">Hunting Lazarus Part IX: The Google Mirror</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://blog.fox-it.com/2026/05/22/remotepe-the-lazarus-rat-that-lives-in-memory/">RemotePE: The Lazarus RAT that lives in memory</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://layerzero.network/publications/kelpdao-incident-report.pdf">LayerZero Labs KelpDAO Incident Report</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://www.chainalysis.com/blog/ofac-sanctions/">OFAC and Crypto Crime: Every OFAC Specially Designated National with Identified Cryptocurrency Addresses</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://quetzal.bitso.com/p/interview-with-the-chollima-viii">Interview with the Chollima VIII</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p><a href="https://open.spotify.com/episode/0N705DBy9xcqZJPbNf5oKz">Eleven Hours: Inside the Lazarus Operator&rsquo;s Disk After the Fake Interview Campaign</a>&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:15">
<p><a href="https://krypt3ia.wordpress.com/2026/05/19/threat-intelligence-report-dprk-activity-evolution-through-campaign-linkage/">DPRK Activity Evolution Through Campaign Linkage</a>&#160;<a href="#fnref:15" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:16">
<p><a href="https://asec.ahnlab.com/ko/93804">2026년 4월 국내외 금융권 관련 보안 이슈</a>&#160;<a href="#fnref:16" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:17">
<p><a href="https://asec.ahnlab.com/en/93932/">Crypto Guest at Dawn Endpoint (Midnight) ransomware analysis</a>&#160;<a href="#fnref:17" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:18">
<p><a href="https://www.bridewell.com/insights/white-papers/detail/cyber-threat-intelligence-report-2026">Cyber Threat Intelligence Report 2026</a>&#160;<a href="#fnref:18" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item><item><title>LW20: IT worker networks, developer access, and bridge risk</title><link>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w20/</link><pubDate>Mon, 18 May 2026 00:00:00 +0000</pubDate><guid>https://lastweek.lazarus.day/last-week-in-dprk-cyber-2026-w20/</guid><description>&lt;h2 id="executive-summary">Executive Summary&lt;/h2>
&lt;p>DPRK reporting last week connected fraudulent employment, developer compromise, and cryptocurrency theft more tightly than before. Investigations into Beejern and THORSwap traced suspected IT worker activity through front companies, developer identities, repository access, and merged wallet-integration changes. A separate account-rental approach showed how remote access to a local laptop can defeat hiring-platform controls.&lt;/p></description><content:encoded><![CDATA[<h2 id="executive-summary">Executive Summary</h2>
<p>DPRK reporting last week connected fraudulent employment, developer compromise, and cryptocurrency theft more tightly than before. Investigations into Beejern and THORSwap traced suspected IT worker activity through front companies, developer identities, repository access, and merged wallet-integration changes. A separate account-rental approach showed how remote access to a local laptop can defeat hiring-platform controls.</p>
<p>The technical reporting covered developer malware, bridge verification failure, and <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> phishing. OtterCookie and MoonPeak supported sustained access to developer and cryptocurrency targets, while the KelpDAO case showed how a compromised verification path could unlock assets without exploiting a token contract. AI appeared both as an attacker aid and as a target-rich layer in recruiting, finance, and software development.</p>
<h2 id="key-trends">Key Trends</h2>
<h3 id="1-it-worker-operations-reached-code-and-trusted-workstations">1. IT worker operations reached code and trusted workstations</h3>
<p>NorthScan linked Beejern to a network of suspected DPRK developer personas and related companies through reused identities, exposed credentials, shared contact details, and fabricated staff images.<sup id="fnref:1"><a href="#fn:1" class="footnote-ref" role="doc-noteref">1</a></sup> At THORSwap, a suspected DPRK worker submitted eight pull requests to SwapKit, with at least three changes to wallet and chain integrations merged.<sup id="fnref:2"><a href="#fn:2" class="footnote-ref" role="doc-noteref">2</a></sup> Another operator offered to rent an Upwork identity and asked the target to install AnyDesk, illustrating how locally hosted laptops can bypass location checks.<sup id="fnref:3"><a href="#fn:3" class="footnote-ref" role="doc-noteref">3</a></sup></p>
<p>Forensic material from a <a href="https://lazarus.day/actors/lazarus/">Lazarus</a>-attributed fake-interview pipeline added an operator-side view of persona creation, provisioning, and targeting workflows.<sup id="fnref:4"><a href="#fn:4" class="footnote-ref" role="doc-noteref">4</a></sup> Together, these cases place employment fraud inside the same risk model as repository access, remote administration, and credential theft.</p>
<h3 id="2-developer-automation-enabled-surveillance-and-supply-chain-access">2. Developer automation enabled surveillance and supply chain access</h3>
<p><a href="https://lazarus.day/actors/contagiousinterview/">Contagious Interview</a> activity abused npm lifecycle scripts and VS Code folder-open tasks to execute code during routine developer work.<sup id="fnref:5"><a href="#fn:5" class="footnote-ref" role="doc-noteref">5</a></sup> OtterCookie then maintained live sessions and collected clipboard data, keystrokes, screenshots, browser secrets, wallets, <code>.env</code> files, SSH material, and cloud or source-control credentials.<sup id="fnref:6"><a href="#fn:6" class="footnote-ref" role="doc-noteref">6</a></sup> A <a href="https://lazarus.day/actors/velvetchollima/">VELVET CHOLLIMA</a> campaign used a signed trading-app MSI, GitLab-hosted stages, scheduled tasks, and MoonPeak to monitor cryptocurrency-focused victims.<sup id="fnref:7"><a href="#fn:7" class="footnote-ref" role="doc-noteref">7</a></sup></p>
<p>These chains target the credentials around code, not just the endpoint. A compromised developer can expose repositories, package publishing, CI/CD, cloud accounts, and wallet operations.</p>
<h3 id="3-crypto-theft-combined-infrastructure-compromise-with-laundering">3. Crypto theft combined infrastructure compromise with laundering</h3>
<p>The KelpDAO analysis attributed the theft to a forged cross-chain message path after Unichain RPC infrastructure was compromised. A 1-of-1 verifier design accepted the false attestation, while protocols requiring independent attestations were not affected in the same way.<sup id="fnref:8"><a href="#fn:8" class="footnote-ref" role="doc-noteref">8</a></sup> Arkham&rsquo;s longer review placed such theft alongside AppleJeus lures, exchange compromises, bridge use, THORChain laundering, and Bitcoin fund splitting.<sup id="fnref:9"><a href="#fn:9" class="footnote-ref" role="doc-noteref">9</a></sup></p>
<p>CrowdStrike also reported a sharp rise in DPRK-linked digital asset theft and described supply chain compromise, recruiter lures, cloud access, and synthetic identities across financial targets.<sup id="fnref:10"><a href="#fn:10" class="footnote-ref" role="doc-noteref">10</a></sup> The common control problem spans signer endpoints, bridge verification, cloud sessions, developer access, and post-theft fund movement.</p>
<h3 id="4-ai-accelerated-established-operations">4. AI accelerated established operations</h3>
<p>Google GTIG observed <a href="https://lazarus.day/actors/apt45/">APT45</a> using AI for high-volume CVE analysis and proof-of-concept validation.<sup id="fnref:11"><a href="#fn:11" class="footnote-ref" role="doc-noteref">11</a></sup> A separate assessment identified recruiting, developer assistance, fraud detection, and financial AI systems as likely access and theft targets because they hold sensitive data and delegated privileges.<sup id="fnref:12"><a href="#fn:12" class="footnote-ref" role="doc-noteref">12</a></sup></p>
<p>The evidence does not point to an entirely new operating model. It indicates that DPRK actors can apply AI to vulnerability research and identity deception while continuing to rely on familiar trust failures.</p>
<h3 id="5-kimsuky-mixed-phishing-with-legitimate-remote-services">5. Kimsuky mixed phishing with legitimate remote services</h3>
<p>Logpresso documented <a href="https://lazarus.day/actors/kimsuky/">Kimsuky</a> campaigns using LNK and JSE lures, PowerShell payloads, GitHub, Microsoft CDN, GitHub OAuth, and VS Code tunnels.<sup id="fnref:13"><a href="#fn:13" class="footnote-ref" role="doc-noteref">13</a></sup> Another campaign used a phishing LNK followed by Dropbox and GitHub stages, scheduled-task persistence, and a reflectively loaded AsyncRAT variant.<sup id="fnref:14"><a href="#fn:14" class="footnote-ref" role="doc-noteref">14</a></sup> Kaspersky&rsquo;s PebbleDash and AppleSeed research added HelloDoor, httpMalice, MemLoad/httpTroy, HappyDoor, DWAgent, Dropbox, and Cloudflare tunnels to the toolset.<sup id="fnref:15"><a href="#fn:15" class="footnote-ref" role="doc-noteref">15</a></sup></p>
<p>For defenders, attachment inspection alone is insufficient. Monitoring should connect script execution with new GitHub or Dropbox access, VS Code tunnels, remote administration tools, and unusual OAuth use.</p>
<h2 id="what-to-watch">What to Watch</h2>
<p>Review contractor and employee access to source repositories with the same rigor applied to production credentials. For crypto and fintech teams, repository permissions, wallet integrations, bridge verifiers, cloud sessions, and remote-access software should be investigated as one connected trust chain.</p>
<h2 id="reports-reviewed">Reports Reviewed</h2>
<div class="footnotes" role="doc-endnotes">
<hr>
<ol>
<li id="fn:1">
<p><a href="https://northscan.co/articles/beejern-llc">Beejern: DPRK IT Worker Front Company Network</a>&#160;<a href="#fnref:1" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:2">
<p><a href="https://archive.md/5mrJC">A suspected DPRK IT worker was employed at THORSwap</a>&#160;<a href="#fnref:2" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:3">
<p><a href="https://archive.md/kvuMA">A North Korean recruiter just tried to pay me $300/month to launder his Upwork identity</a>&#160;<a href="#fnref:3" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:4">
<p><a href="https://open.spotify.com/episode/4fCxS9Q4n82tf8fRgsMRCZ">The Factory: How a Lazarus-Attributed Credential Pipeline Collected Its Own Operators</a>&#160;<a href="#fnref:4" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:5">
<p><a href="https://opensourcemalware.com/blog/malware-abuses-vscode-lifecycle-scripts">How malware abuses npm lifecycle scripts and VS Code tasks</a>&#160;<a href="#fnref:5" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:6">
<p><a href="https://redasgard.com/blog/hunting-lazarus-part8-ottercookie">Hunting Lazarus Part VIII: OtterCookie</a>&#160;<a href="#fnref:6" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:7">
<p><a href="https://hybrid-analysis.blogspot.com/2026/05/velvet-chollima-infostealer-campaign.html">VELVET CHOLLIMA Infostealer Campaign Using Trading App as Lure</a>&#160;<a href="#fnref:7" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:8">
<p><a href="https://archive.md/Cesz9">The Case For Modular Security Post-LayerZero/KelpDAO</a>&#160;<a href="#fnref:8" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:9">
<p><a href="https://info.arkm.com/research/lazarus-group-the-north-korean-hacking-syndicates-on-chain-footprint">Lazarus Group: The North Korean Hacking Syndicate’s On-Chain Footprint</a>&#160;<a href="#fnref:9" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:10">
<p><a href="https://www.crowdstrike.com/en-us/press-releases/crowdstrike-2026-financial-services-threat-landscape-report/">CrowdStrike 2026 Financial Services Threat Landscape Report: North Korean Adversaries Steal Billions in Digital Assets</a>&#160;<a href="#fnref:10" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:11">
<p><a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">GTIG AI Threat Tracker: Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access</a>&#160;<a href="#fnref:11" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:12">
<p><a href="https://krypt3ia.wordpress.com/2026/05/14/18837/">APT Operations Against AI Systems</a>&#160;<a href="#fnref:12" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:13">
<p><a href="https://logpresso.com/ko/blog/2026-05-15-1Q-Kimsuky-report">1분기 DPRK Operation Kimsuky 분석</a>&#160;<a href="#fnref:13" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:14">
<p><a href="https://mp.weixin.qq.com/s?__biz=MzUyMjk4NzExMA==&amp;mid=2247508584&amp;idx=1&amp;sn=3983faed8f799809ecc23eb552e73548&amp;scene=178">APT-C-55（Kimsuky）组织依托GitHub+Dropbox分发恶意载荷的攻击活动分析</a>&#160;<a href="#fnref:14" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
<li id="fn:15">
<p><a href="https://securelist.com/kimsuky-appleseed-pebbledash-campaigns/119785/">Disclosing new PebbleDash-based tools by Kimsuky</a>&#160;<a href="#fnref:15" class="footnote-backref" role="doc-backlink">&#x21a9;&#xfe0e;</a></p>
</li>
</ol>
</div>]]></content:encoded></item></channel></rss>