#genians
Glaciated Plateau things: stopped by the Jennings Prairie and caught genians in bloom!!!!!!; the Miller esker
September 16, 2025 at 2:54 AM
I FUCKIN KNEW IT

That's not a deepfake! That's just a fake!
September 15, 2025 at 12:09 AM
"HWP 문서 내부에 악성 OLE 삽입 공격: FlowerPower APT 캠페인 Github C2 사용" published by Genians. #Kimsuky, #FlowerPower, #CTI, #OSINT, #LAZARUS https://www.genians.co.kr/blog/flowerpower
November 30, 2023 at 12:30 PM
South Korean researchers uncover another cyber-espionage campaign from the North
South Korean researchers uncover another cyber-espionage campaign from the North
A group tracked as APT37 or ScarCruft is once again phishing South Korean organizations with national security interests, according to analysts at cybersecurity firm Genians.
buff.ly
May 14, 2025 at 11:42 AM
--Operation Synergia III busts 94 alleged cybercriminals,
--DPRK's Konni Group used KakaoTalk to spread info-stealing malware,
--Japan was hit by 226 ransomware attacks in 2025,
--Chinese attack on Costa Rica's electricity institute sparks diplomatic row, 2/7
March 16, 2026 at 1:45 PM
Genians says North Korea's Konni Group used KakaoTalk in a spear-phishing campaign with emails offering what appeared to be appointments as lecturers on North Korean human rights issues
www.upi.com/Top_News/Wor...
North Korea hackers used KakaoTalk in spear-phishing campaign, report says - UPI.com
North Korea-linked hackers carried out a spear-phishing campaign that used the South Korean messaging platform KakaoTalk to spread malware, according to a report Monday.
www.upi.com
March 16, 2026 at 11:06 AM
韓国のサイバーセキュリティー企業Geniansが10日に明らかにしたところによると、北朝鮮政府系のハッカー集団「Kimsuky」が大規模言語モデル(LLM)ツールを構築し、サイバー攻撃の自動化、盗んだデータの分析、より説得力のあるフィッシング攻撃の展開に役立つソフトウエアを収集していた。 bit.ly/4znoXKO
北朝鮮ハッカー集団がサイバー攻撃用のAIツール開発=韓国企業
韓国のサイバーセキュリティー企業Geniansが10日に明らかにしたところによると、北朝​鮮政府系のハッカー集団「Kimsuky」が大規模言語‌モデル(LLM)ツールを構築し、サイバー攻撃の自動化、盗んだデータの分析、より説得力のあるフィッシン​グ攻撃の展開に役立つソフトウエアを収​集していた。
bit.ly
August 10, 2026 at 3:55 AM
Fresh evidence

Genians links Kimsuky-associated GitPower to AI-generated decoys, local-LLM experimentation, ZIP-contained LNK files, obfuscated PowerShell, Git-hosted content, and scheduled tasks.
August 10, 2026 at 1:31 PM
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own …
#hackernews #news
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the
thehackernews.com
August 11, 2026 at 9:24 AM
A group tracked as APT37 or ScarCruft is once again phishing South Korean organizations with national security interests, according to analysts at cybersecurity firm Genians therecord.media/apt37-scarcr...
South Korean researchers uncover another cyber-espionage campaign from the North
A group tracked as APT37 or ScarCruft is once again phishing South Korean organizations with national security interests, according to analysts at cybersecurity firm Genians.
therecord.media
May 13, 2025 at 4:00 PM
Genians Security Center uncovers an APT37 campaign that used social networking as an initial access vector. Two Facebook accounts set to North Korea-linked locations were used to screen targets, build trust, and move conversations to Messenger. www.genians.co.kr/en/blog/thre...
April 13, 2026 at 9:11 AM
The Genians Security Center has analysed a new form of the APT37 group's RoKRAT. The threat actor embeds "Cmd" or "PowerShell" commands within shortcut files with the LNK extension for its attacks. www.genians.co.kr/blog/threat_...
August 5, 2025 at 9:41 AM
Genians reports an APT37 campaign where fake casting/interview outreach delivers a trojanised HWP document. The chain relies on embedded OLE content and user clicks to start execution, then uses DLL side-loading to evade detection. www.genians.co.kr/en/blog/thre...
January 5, 2026 at 11:22 AM
Genians reports on the Kimsuky APT group using ChatGPT to generate deepfake South Korean military ID cards for phishing. The campaign used batch files and AutoIt scripts to evade anti-virus defences. www.genians.co.kr/en/blog/thre...
September 16, 2025 at 3:26 PM
Genians reports APT37 hackers abusing Google’s Find Hub to track and remotely reset Android devices via stolen Google credentials.

No Android exploit - just legitimate tools misused.
Google urges users to enable 2-Step Verification and consider Advanced Protection.

#CyberSecurity #AndroidSecurity
November 11, 2025 at 3:33 PM
South Korean researchers uncover another cyber-espionage campaign from the North
South Korean researchers uncover another cyber-espionage campaign from the North
A group tracked as APT37 or ScarCruft is once again phishing South Korean organizations with national security interests, according to analysts at cybersecurity firm Genians.
therecord.media
May 13, 2025 at 5:07 PM
北朝鮮ハッカー集団「Kimsuky」、サイバー攻撃用AIツールを独自開発か - BigGo ファイナンス

... マルウェア開発やデータ分析、フィッシング攻撃の自動化にAIを統合する能力の獲得を進めていることが示唆された。 Geniansの報告書によると、Kimsukyは ...
finance.biggo.jp/news/22ef246...
北朝鮮ハッカー集団「Kimsuky」、サイバー攻撃用AIツールを独自開発か — BigGo ファイナンス
韓国のセキュリティ企業Geniansの調査で、北朝鮮のハッカー集団KimsukyがOllamaやGPT4Allなどの大規模言語モデル管理ツールをローカル環境に構築し、サイバー攻…
finance.biggo.jp
August 10, 2026 at 12:30 PM
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware

The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware …
#hackernews #microsoft #news
Fake Microsoft Alerts Used to Deploy North Korean NarwhalRAT Malware
The North Korean state-sponsored hacking group known as ScarCruft (aka APT37) has been observed using spear-phishing messages impersonating Microsoft Account security notifications to deliver malware called NarwhalRAT. "The attack email contained a message impersonating an MS account security alert," the Genians Security Center (GSC) said. "It was designed to create concern over possible
thehackernews.com
June 17, 2026 at 12:36 AM