Other malicious domains from this 🇰🇵 campaign:
precommit-nyx.vercel[.]app
precommit-chk-one.vercel[.]app
tanxilabs[.]com
code-beautify[.]com
precommit-chk.vercel[.]app
gitconfig-nyx.vercel[.]app
Some of them were also used in phishing attacks.
#dprk#malware#github
Someone on Darkforums is allegedly leaking 300,000+ records and 10,000+ users PII from Polymarket. Seems more like an API scrape than a breach though. Comes with some POC scripts and a "redteam" report.
#polymarket#breach#darkweb
Fake personas passing as web developers, brand impersonation, use of AI copilots for job interview...
Following @ZachXBT’s DPRK workers investigation, we used our STEALINT platform to see what infostealers could uncover.
Here are our findings: https://t.co/Bhqt2glXtb
#dprk
1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.
I spent long hours going through all of it, none of which has ever been publicly released.
It revealed an intricate ~$1M/month scheme of fraudulent identities, forged legal documents, and crypto-to-fiat conversion.
Enjoy the findings!
Des centaines de milliers de documents et de photos d'identité dans la nature... l'hémorragie chez les fédérations françaises de sport se poursuit : découvrez notre Hebdo Cybercrime du 2 mars !
https://t.co/eyzCdQN4S6
MANOMANO piraté, des données personnelles de députés et de sénateurs publiées... Découvrez notre Hebdo Cybercrime du 9 février !
https://t.co/xUX0O7D6m0
#darkweb#ransomware#0apt#leak
Rapid7 confirms the supply chain attack was used to deliver the Chrysalis backdoor which they attribute to the Chinese APT group Lotus Blossom. Technical report and IOCs: https://t.co/4tAL3h3pwL
#supplychainattack#lotusblossom
🚨Notepad++ targeted in supply chain attack: its update infrastructure was hijacked, letting attackers redirect some of the update traffic to malicious servers between June–Dec 2025. Infrastructure is now secured according to the Notepad++ team.
https://t.co/sp8QOUbIku
🏴 Encore une semaine noire pour les données françaises... Nous venons de publier notre Hebdo Cybercrime du 2 février ! Vous y trouverez les événements liés au cybercrime ayant impacté la France ces sept derniers jours.
https://t.co/PkQvW44j3V
#darkweb#stealer#leak#ransomware
Someone is allegedly selling an access to an extranet portal of the main french telecom company Orange, where you can lookup phones and view customers information. Price is very cheap so not sure if legit.
#darkweb#access#Orange
Silent Push is tracking a sophisticated phishing campaign linked to #SLSH that is mirroring TTPs recently reported by @Okta and @BleepingComputer.
Read full blog here: https://t.co/QQXPshVtyu
#cti#soc#ir#cybersec#threat#scatteredspider
Another new pro-Russian hacktivist group, Russian Legion, has formed a new cluster of pro-Russian hacktivist groups and are currently targeting #Denmark
Claimed DDoS atm, but they could shift attacks if the campaign is sustained.
Old Data, New Actor: Investigating Solonik’s Alleged Instagram 17 M Leak
This report documents how StealthMole was used to trace the origins, movement, and rebranding of this dataset across forums, Telegram channels, and domains, ultimately challenging Solonik’s claims and highlighting the growing trend of breach recirculation under false timelines.
https://t.co/9sxO0ExJ7E