Fake personas passing as web developers, brand impersonation, use of AI copilots for job interview...
Following @ZachXBT’s DPRK workers investigation, we used our STEALINT platform to see what infostealers could uncover.
Here are our findings: https://t.co/Bhqt2glXtb
#dprk
Other malicious domains from this 🇰🇵 campaign:
precommit-nyx.vercel[.]app
precommit-chk-one.vercel[.]app
tanxilabs[.]com
code-beautify[.]com
precommit-chk.vercel[.]app
gitconfig-nyx.vercel[.]app
Some of them were also used in phishing attacks.
#dprk#malware#github
NK hackers are targeting software developers and job applicants with fake coding interview tasks.
They send you a GitHub repository link and ask you to git clone it to complete a programming test.
Inside the repo, they hide a malicious Git Hook (a small script that Git runs automatically).
The hook is placed at .githooks/pre-commit (not in the usual .git/hooks folder).
As soon as you run git commit (a completely normal thing every developer does), the hook triggers automatically.
The script quickly checks your operating system (Mac, Linux, or Windows), then silently downloads and runs the real malware from precommit[.]vercel[.]app.
The downloaded malware belongs to Lazarus’s toolkit InvisibleFerret and Beavertail backdoors.
Someone on Darkforums is allegedly leaking 300,000+ records and 10,000+ users PII from Polymarket. Seems more like an API scrape than a breach though. Comes with some POC scripts and a "redteam" report.
#polymarket#breach#darkweb
DPRK IT workers continue to infiltrate corporate networks using fraudulent identities. Senior Threat Intelligence Analyst Eli Woodward (@ElijahWoodward9) details how these adversaries leverage freelance platforms to bypass traditional hiring controls.
- Network traffic correlates these operations with AI developer tools and platforms like Workana.
- Operators use American and Latvian residential IPs alongside VPNs to mask their true locations.
Read Eli's full briefing: https://t.co/6prMOAKaoJ
#CyberSecurity #ThreatHunting #CyberThreatActors #DPRK #InfoSec
1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.
I spent long hours going through all of it, none of which has ever been publicly released.
It revealed an intricate ~$1M/month scheme of fraudulent identities, forged legal documents, and crypto-to-fiat conversion.
Enjoy the findings!
Des centaines de milliers de documents et de photos d'identité dans la nature... l'hémorragie chez les fédérations françaises de sport se poursuit : découvrez notre Hebdo Cybercrime du 2 mars !
https://t.co/eyzCdQN4S6
Les données disponibles sur https://t.co/Yz6AmwMTfb sont désormais interrogeables via un serveur MCP dédié en experimentation, vos retours sont bienvenus !
💻 Le code est ouvert et accessible sur GitHub :
https://t.co/AmY04V22TH
Pour en savoir plus : https://t.co/V7UJrc6uUq
MANOMANO piraté, des données personnelles de députés et de sénateurs publiées... Découvrez notre Hebdo Cybercrime du 9 février !
https://t.co/xUX0O7D6m0
#darkweb#ransomware#0apt#leak
It turned out there are many more payloads used in the Notepad++ attack! To stay undetected, its masterminds were COMPLETELY changing execution chains about every month.
Here are more IPs used in the attack:
45.76.155[.]202
45.32.144[.]255
Read below for many other IoCs! [1/8]
Rapid7 confirms the supply chain attack was used to deliver the Chrysalis backdoor which they attribute to the Chinese APT group Lotus Blossom. Technical report and IOCs: https://t.co/4tAL3h3pwL
#supplychainattack#lotusblossom
🚨Notepad++ targeted in supply chain attack: its update infrastructure was hijacked, letting attackers redirect some of the update traffic to malicious servers between June–Dec 2025. Infrastructure is now secured according to the Notepad++ team.
https://t.co/sp8QOUbIku
🏴 Encore une semaine noire pour les données françaises... Nous venons de publier notre Hebdo Cybercrime du 2 février ! Vous y trouverez les événements liés au cybercrime ayant impacté la France ces sept derniers jours.
https://t.co/PkQvW44j3V
#darkweb#stealer#leak#ransomware
Someone is allegedly selling an access to an extranet portal of the main french telecom company Orange, where you can lookup phones and view customers information. Price is very cheap so not sure if legit.
#darkweb#access#Orange