Being able to represent the whole story is critical to threat actor attribution. Can your platform represent analytically relevant lunch orders? ๐ PoL is now "Pattern of Lunch"
https://t.co/dZmvIGJMID
Weโre sharing our completed post-mortem on the April 18th incident, prepared with @Mandiant and @CrowdStrike. We are publishing both an executive summary and the full report at the link below.
Over the past four weeks, weโve worked with hundreds of partners to help them understand their current security posture, and harden it where appropriate. Weโll continue this work, alongside taking additional proactive steps for the benefit of not only our partners, but also the ecosystem as a whole.
We want to extend our thanks to our partners for their support and patience this past month. Thereโs a reason that over $12 billion has moved across the network in the past four weeks, and why the worldโs most valuable asset issuers have stood by our side: they believe in us, in what the LayerZero protocol has to offer, and in the value of modular, isolated, application-controlled security.
The work continues. And we look forward to continue showing up for the applications that trust us with their business, as well as the broader ecosystem.
https://t.co/7bILN6dPJz
1/ Recently an unnamed source shared data exfiltrated from an internal North Korean payment server containing 390 accounts, chat logs, crypto transactions.
I spent long hours going through all of it, none of which has ever been publicly released.
It revealed an intricate ~$1M/month scheme of fraudulent identities, forged legal documents, and crypto-to-fiat conversion.
Enjoy the findings!
I strongly suspect that @DriftProtocol is not the only team this group has been targeting - so if you read this article and you are worried any of it might sound familiar, please reach out to @SEAL_911 and we will help you go through it. Let's not allow another hack by this team.
I beg everyone in crypto to read this in full.
I expected this to be another case of social engineering, likely some recruiter/job offer shit.
I was very wrong.
And the depth of the operation and personas makes me think they already have multiple other teams on lock.
๐ณ
We are still looking at the axios supply chain compromise, but weโve attributed it to UNC1069, a suspected DPRK actor, who we covered in a blog this February. They are financially-motivated and historically DPRK uses these incidents to target crypto. https://t.co/RIeOp14UNU
UNC6201 is exploiting a high-risk zero-day (CVSS 10.0) in Dell RecoverPoint for Virtual Machines.
This PRC-nexus actor has leveraged the vulnerability since mid-2024 to maintain persistent access, and distribute GRIMBOLT backdoor.
๐ Learn more:
https://t.co/Q92lmOaW8X
๐จHot off the Press๐จ
๐จ๐ณ nexus actor, UNC6201 exploiting CVE-2026-22769 to move laterally and deploy SLAYSTYLE, BRICKSTORM and a new novel backdoor, GRIMBOLT
๐
https://t.co/mey2ifpEqU
GTIGโs latest AI Threat Tracker Report is out! APT31, UNC795 and APT41 using AI to support development, testing and research.
https://t.co/0ogkw4duPD
A few potential new domains (currently unknown on VT) related to recent North Korean threat activity reported by @Mandiant.
We observed these through a small pattern in our DNS data.
- Domains resolving to the CIDR 134.45.0.0/16
- Where the IP has been associated a low number of domains.
- Where domain name is relatively short, mostly alphabetical and uses a .com TLD.
This pattern may sound broad, but it matches on only 6 active domains across 3 unique IP's since 2025, with 4 of these domains referenced in the recent UNC1069 report.
The two remaining domains resolve to 134.45.83[.]95, which has previously been linked to the now inactive doc-bridge[.]com.
Based on the overlapping patterns and similar "dream" references also observed by Mandiant, we believe that these domains are likely to be related.
there's anti-disassembly, anti-debugging, anti-VM, etc. when identify malware techniques.
now there's "anti-LLM": https://t.co/dql86W2d2F
such as including magic strings that cause Claude sessions to be terminated for "safety reasons".
North Korea threat actor UNC5342 is using EtherHiding, the first time we have observed a nation-state use this technique. ๐จ
The TTP is being used in a social engineering campaign that leads to cryptocurrency heists and espionage.
Read the blog post: https://t.co/JGnXcAQfoQ
BRICKSTORM malware used by suspected China-nexus actor, UNC5221, in stealthy espionage campaign.
- Avg dwell time: 393 days.
- Targets: US legal, SaaS, BPOs & tech firms.
We have released a scanner, IOCs, and guidance to help defenders.
Full analysis: https://t.co/wM3OFsR5Ec
๐ง ๐ก๐ฒ๐ ๐ฏ๐น๐ผ๐ด: "๐ง๐ต๐ฟ๐ฒ๐ฒ ๐๐ฎ๐๐ฎ๏ฟฝ๏ฟฝ๏ฟฝ๐๐ ๐ฅ๐๐ง๐ ๐๐ผ๐บ๐ถ๐ป๐ด ๐ณ๐ผ๐ฟ ๐ฌ๐ผ๐๐ฟ ๐๐ต๐ฒ๐ฒ๐๐ฒ"
Read about PondRAT, ThemeForestRAT and RemotePE - three RATs we encountered during incident response involving the Lazarus group.
Check the indicators and don't let them steal your cheese!
#ThreatIntel #Lazarus #DFIR
https://t.co/JJ71mCw4kp
CORNFLAKE.V3 malware spotted in an access-as-a-service operation using the ClickFix technique. ๐ฅฃ
UNC5518 uses fake CAPTCHA pages for access, which UNC5774 then leverages to deploy the CORNFLAKE.V3.
Learn more: https://t.co/zRdEp0ctKm