#APT38
Malicious versions of three Rust packages, one of which Wiz finds in more than 35 percent of environments, ran a backdoor during compilation. The attacker infrastructure overlaps heavily with recent North Korean supply chain attacks.

#APT38 #APT #infosec
Hijacked Rust package backdoors any machine that builds it
Nation-State · IntelFusions threat intelligence
www.intelfusions.com
August 20, 2026 at 11:22 PM
Noord-Korea's 'cyberzwaard' roofde 'honderden miljoenen' van banken
Noord-Korea's 'cyberzwaard' roofde 'honderden miljoenen' van banken
Door het online infiltreren van banken heeft de Noord-Koreaanse hackgroep APT38 honderden miljoenen dollars verdiend, zegt een internetbeveiligingsbedrijf.
nos.nl
July 26, 2026 at 2:57 AM
🚨 North Korea's Sapphire Sleet behind Mastra AI supply chain attack! 141 malicious NPM packages published after maintainer account compromise. Developers, check for 'easy-day-js' dependency now! #SupplyChain #NPM #CyberAttack

🌐 cyber[.]netsecops[.]io
North Korea
Microsoft attributes a major supply chain attack on the Mastra AI framework to the North Korean threat actor Sapphire Sleet (APT38), involving malicious NPM packages.
cyber.netsecops.io
June 23, 2026 at 7:12 PM
🚨 North Korea's Sapphire Sleet behind Mastra AI supply chain attack! 141 malicious NPM packages published after maintainer account compromise. Developers, check for 'easy-day-js' dependency now! #SupplyChain #NPM #CyberAttack

🌐 cyber[.]netsecops[.]io
North Korea
Microsoft attributes a major supply chain attack on the Mastra AI framework to the North Korean threat actor Sapphire Sleet (APT38), involving malicious NPM packages.
cyber.netsecops.io
June 22, 2026 at 5:50 PM
This PowerShell sample attributed to APT38 is already noisy af when scanned with THOR and the .bat that gets dropped also triggers a rule

PS1

https://
virustotal.com/gui/file/675bb
a15b954318398f1a34aef4ecffce515feb35130fb12a8…

— from @cyb3rops (https://x.com/cyb3rops/status/2068244526611788001)
June 20, 2026 at 1:15 PM
🟢 Inside APT38: How North Korean Hackers Steal Hundreds of Millions of Dollars from Banks

🗨️ If you imagine North Korea as having maybe three computers total—one where Kim Jong Un plays League of Legends and anoth…

#security
Inside APT38: How North Korean Hackers Steal Hundreds of Millions of Dollars from Banks
Read more
hackmag.com
May 2, 2026 at 12:30 PM
BlueNoroff’s AI-Powered Zoom Trap: How Fileless PowerShell Pwns Your Crypto in 5 Minutes + Video

Introduction: North Korea’s Lazarus subgroup, BlueNoroff (aka APT38), has launched a sophisticated global campaign targeting cryptocurrency and Web3 professionals. This operation leverages AI-generated…
BlueNoroff’s AI-Powered Zoom Trap: How Fileless PowerShell Pwns Your Crypto in 5 Minutes + Video
Introduction: North Korea’s Lazarus subgroup, BlueNoroff (aka APT38), has launched a sophisticated global campaign targeting cryptocurrency and Web3 professionals. This operation leverages AI-generated deepfake Zoom lures and a “ClickFix” clipboard injection attack to deploy a fileless PowerShell implant that achieves full system compromise in under five minutes. Learning Objectives: Identify the ClickFix social engineering pattern and analyze its multi-platform execution indicators.
undercodetesting.com
April 29, 2026 at 8:43 AM
New Sapphire Sleet attack against macOS users detailed
New Sapphire Sleet attack against macOS users detailed
New Sapphire Sleet attack against macOS users detailed The Register reports that North Korean hacking operation Sapphire Sleet, also known as APT38, has sought to compromise macOS users with…
bit.ly
April 23, 2026 at 1:46 PM
マイクロソフト専門家が北朝鮮の攻撃者がmacOSユーザーを「非常に信頼性の高い感染チェーン」で狙っていることを警告…

マイクロソフトが、北朝鮮のサファイアスリート(APT38)が偽りの求人詐欺で西側企業を標的にしていることを警告悪意のあるZoomの模造品が暗号資産を盗むための情報盗難ツールを配布キャンペーンはmacOSユーザーを対象、Appleが攻撃をブロックするための自動保護を配信北朝鮮国営の脅威行為者であるサファイアス
マイクロソフト専門家が北朝鮮の攻撃者がmacOSユーザーを「非常に信頼性の高い感染チェーン」で狙っていることを警告…
マイクロソフトが、北朝鮮のサファイアスリート(APT38)が偽りの求人詐欺で西側企業を標的にしていることを警告悪意のあるZoomの模造品が暗号資産を盗むための情報盗難ツールを配布キャンペーンはmacOSユーザーを対象、Appleが攻撃をブロックするための自動保護を配信北朝鮮国営の脅威行為者であるサファイアス
blackhatnews.tokyo
April 17, 2026 at 1:27 PM
📰 Bitrefill Tuding Grup Hacker Lazarus Korea Utara Dalangi Serangan Siber ke Platformnya

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2026/03/22/bitrefill-diserang-hacker-korea-utara-lazarus-bluenoroff/

#apt
38#apt38t#beritaTeknologie#bitrefilln#bluenoroffe#hackerLazarusd#insidenSibera href="/hashtag/kea" class="hover:underline text-blue-600 dark:text-sky-400 no-card-link">#kea
March 22, 2026 at 4:55 AM
Famous Chollima Exploits Malicious npm Packages: A Deep Dive into the Supply Chain Threat

Recent reports from security researchers, including Socket and Kieran Miyamoto, have unveiled a sophisticated supply chain attack orchestrated by the infamous North Korean nation-state actor, Famous Chollima.…
Famous Chollima Exploits Malicious npm Packages: A Deep Dive into the Supply Chain Threat
Recent reports from security researchers, including Socket and Kieran Miyamoto, have unveiled a sophisticated supply chain attack orchestrated by the infamous North Korean nation-state actor, Famous Chollima. This group, also known by various monikers such as APT38, Lazarus Group, and TraderTraitor, has been implicated in deploying more than two dozen malicious npm (Node Package Manager) packages designed to pilfer sensitive data from software developers.
allsafeus.com
March 4, 2026 at 4:19 PM
Lazarus Group Leverages Medusa Ransomware Against Healthcare: A Deep Dive

The cybersecurity landscape continues its relentless evolution, and a recent development highlights the persistent threat posed by advanced persistent threat (APT) groups. Our intelligence at AllSafeUs Research Labs…
Lazarus Group Leverages Medusa Ransomware Against Healthcare: A Deep Dive
The cybersecurity landscape continues its relentless evolution, and a recent development highlights the persistent threat posed by advanced persistent threat (APT) groups. Our intelligence at AllSafeUs Research Labs indicates a significant shift in tactics from the North Korean-backed Lazarus Group, also known as APT38 or Hidden Cobra. This notorious entity, historically associated with nation-state espionage and financial theft, appears to have broadened its ransomware repertoire by deploying Medusa ransomware in extortion attacks.
allsafeus.com
February 24, 2026 at 9:17 PM
@waldoj joke is on you, that's actually APT38 and all your crypto was just sent to Pyongyang.
January 3, 2026 at 5:39 AM
WinRAR Finally Gets That 'State-Sponsored' Zero-Day Upgrade Courtesy of Lazarus Group.
PANIC 75% | Lag 0.0h | North Korea's Lazarus Group (APT38) is actively exploiting WinRAR vulnerability CVE-2025-8088, utili
#AfterShockIndex
https://index.deceiver.io/story/story:1766614309:8520
December 24, 2025 at 10:11 PM
The latest update for #Foresiet includes "Modernizing #Cybersecurity Risk Assessment: A #CISO 3.0 Guide for 2026" and "Lazarus Group (APT38 / APT-C-26) Exploits WinRAR Vulnerability CVE-2025-8088 for Archive Poisoning Attacks".

#infosec https://opsmtrs.com/3J3CMGz
Foresiet
One Click Digital Risk Protection platform to protect from digital external threats, detect and prevent breach epidemic from surface, deep and Dark web.
opsmtrs.com
December 24, 2025 at 8:56 PM
The latest update for #Foresiet includes "Lazarus Group (APT38 / APT-C-26) Exploits WinRAR Vulnerability CVE-2025-8088 for Archive Poisoning Attacks" and "The New Mandate: CISA CPG 2.0 and the Evolution of Critical Infrastructure Security".

#cybersecurity #infosec https://opsmtrs.com/3J3CMGz
Foresiet
One Click Digital Risk Protection platform to protect from digital external threats, detect and prevent breach epidemic from surface, deep and Dark web.
opsmtrs.com
December 18, 2025 at 6:40 AM
北朝鮮が米企業に潜入するのを支援したとして5人が有罪答弁

米司法省は、リモートIT労働者詐欺や暗号通貨窃盗を含む、北朝鮮の不正な収益獲得スキームを支援したとして、5人が有罪を認めたと発表しました。 これに関連して、米当局は、ラザルスハッカー集団と関連するAPT38脅威グループが実行した強奪で得られた暗号通貨1,500万ドルの没収を求める措置を発表しました。 仲介役となった4人の米国人と1人のウクライナ人は、自身の身元情報のほか、虚偽または盗まれた身元情報(18人の米国人から盗まれたもの)を使用し、DPRK(北朝鮮)工作員が米企業にリモートワーカーとして雇用されることを可能にしました。…
北朝鮮が米企業に潜入するのを支援したとして5人が有罪答弁
米司法省は、リモートIT労働者詐欺や暗号通貨窃盗を含む、北朝鮮の不正な収益獲得スキームを支援したとして、5人が有罪を認めたと発表しました。 これに関連して、米当局は、ラザルスハッカー集団と関連するAPT38脅威グループが実行した強奪で得られた暗号通貨1,500万ドルの没収を求める措置を発表しました。 仲介役となった4人の米国人と1人のウクライナ人は、自身の身元情報のほか、虚偽または盗まれた身元情報(18人の米国人から盗まれたもの)を使用し、DPRK(北朝鮮)工作員が米企業にリモートワーカーとして雇用されることを可能にしました。 その後、これらの工作員は給与に加え、場合によっては盗んだデータも北朝鮮政府に送金しました。 司法省の発表によると、この5人の行為は全米で136社に影響を与え、DPRK政権に2,200万ドル超の収益をもたらしました。 有罪を認めた5人は以下のとおりです。 オレクサンドル・ディデンコ(Oleksandr Didenko) – 電信詐欺共謀および加重身元盗用の罪を認めました。彼は米国人の身元情報を盗み、それを海外のIT労働者に販売し、その者たちは40の米企業に雇用されました。以前、司法省に差し押さえられたUpWorkSellプラットフォームと関連付けられており、クリスティーナ・マリー・チャップマン(Christina Marie Chapman)の共謀者として特定されています。 エリック・ンテケレゼ・プリンス(Erick Ntekereze Prince) – 電信詐欺共謀の罪を認めました。自身の会社Taggcar Inc.を通じて、盗まれた身元情報を用いる海外IT労働者を64の米企業に就労させ、その過程で8万9,000ドルを得る一方、94万3,000ドルを超える損害を引き起こしました。 オードリカス・ファグナセイ(Audricus Phagnasay)、ジェイソン・サラザール(Jason Salazar)、およびアレクサンダー・ポール・トラビス(Alexander Paul Travis)は、電信詐欺共謀の罪を認めました。彼らは2019年から2022年にかけて前述のスキームに関与し、合計128万ドルの損害を発生させました。トラビスは5万1,000ドルを得ており、ファグナセイとサラザールは3,450ドルから4,500ドルの間を得ていました。 ディデンコは、法定通貨57万ドルと、さらに83万ドル相当の暗号通貨の没収に同意しました。 司法省の発表では、北朝鮮のAPT38によって盗まれ洗浄された総額1,500万ドル超を差し押さえるために提起された2件の民事没収訴訟についても強調しています。 差し押さえ対象の資金は、2023年にパナマ、エストニア、セーシェルに拠点を置く暗号通貨取引プラットフォームを標的とした4件の大規模インシデントに関連しています。これらのサイバー強奪で、合計3億8,200万ドルが盗まれました。 APT38は、これらのハッキングで得た資金を暗号通貨ブリッジ、ミキサー、取引所、OTCトレーダーを通じて洗浄しており、当局はこれまでに1,500万ドルを追跡・差し押さえており、さらなる差し押さえに向けた作業が進行中です。 翻訳元:
blackhatnews.tokyo
December 5, 2025 at 1:16 AM
BlueNoroffが戦術を転換:新たな侵入手法で経営幹部や管理職をターゲットに

北朝鮮とつながりのある脅威グループ BlueNoroff (別名 Sapphire Sleet、APT38、Alluring Pisces) は、金銭的利益を主な目的としながら、攻撃戦術を進化させ続けています。

同グループは戦略を転換し、Web3およびベンチャーキャピタル分野のCレベルの経営幹部、管理職、ブロックチェーン開発者など、価値の高い被害者をターゲットにした、洗練された新しい侵入方法を採用している。

セキュリティ研究者は、GhostCallとGhostHireと呼ばれる2つの異なるキャンペーン...
BlueNoroff Shifts Tactics: Targets C-Suite and Managers with New Infiltration Methods
The North Korean-linked threat group BlueNoroff, also known by aliases including Sapphire Sleet, APT38, and Alluring Pisces, continues to evolve its attack tactics.
gbhackers.com
November 26, 2025 at 12:42 PM
暗号通貨の無駄遣い:ブルーノロフの資金調達と雇用の幻影

BlueNoroff(別名:Sapphire Sleet、APT38、Alluring Pisces、Stardust Chollima、TA444)は、登場以来、主に金銭的利益を目的としており、時間の経過とともに新たな侵入戦略とマルウェアセットを採用してきましたが、SnatchCryptoオペレーションの一環として、依然としてブロックチェーン開発者、経営幹部、Web3/ブロックチェーン業界の管理職を標的としています。今年初め、私たちはBlueNoroffによるSnatchCryptoオペレーションに基づく2つの悪意のあるキャン...
BlueNoroff's latest campaigns: GhostCall and GhostHire
Kaspersky GReAT experts dive deep into the BlueNoroff APT's GhostCall and GhostHire campaigns. Extensive research detailing multiple malware chains targeting macOS, including a stealer suite, fake Zoo...
securelist.com
November 23, 2025 at 8:13 PM
Blockchain investigator ZachXBT has published a report on how the APT38 (Bluenoroff) group laundered $200 million worth of crypto from 25+ hacks to fiat between 2020 and 2023.

paragraph.com/@investigati...
How Lazarus Group laundered $200M from 25+ crypto hacks to fiat from 2020–2023
Table of contents1). Introduction 2). CoinBerry, Unibright, & CoinMetro hacks 3). Nexus Mutual founder hack 4). EasyFi hack 5). Bondly hack 6). Unreported hacks 7). MGNR and PolyPlay hacks 8). bZx hac...
paragraph.com
November 20, 2025 at 1:34 PM
Park Jin HYOK is wanted by the FBI for his role as a hacker for hashtag#DPRK, specifically his affiliation with hashtag#Lazerus group also known as hashtag#APT38.

My starting point was the 4 name/alias variants of his name shared on the hashtag#FBI most wanted page and the image of his face.
November 20, 2025 at 1:31 PM
It's further complicated due to APT38 Lazarus Group which is a Mossad straw for China who seems to have considerable compromising material on everyone.
November 18, 2025 at 9:56 PM
📰 Lima Orang Mengaku Bersalah Bantu Hacker Korea Utara Menyusup ke Perusahaan AS

👉 Baca artikel lengkap di sini: https://ahmandonk.com/2025/11/18/north-korean-it-worker-fraud-five-plead-guilty/

#apt
38#apt38t#cryptot#theftr#lazarush#northa#koreat#remotee#workerd#fraud
November 18, 2025 at 11:27 AM