Microsoft attributes Mastra AI supply chain attack to North Korean hackers Sapphire Sleet

Microsoft warns that a recent supply chain attack on the Mastra AI npm environment was carried out by Sapphire Sleet, a notorious North Korean hacking group known for targeting the financial sector. This latest incident is part of a larger pattern of attacks that exploit open-source distribution channels.

https://osintsights.com/microsoft-attributes-mastra-ai-supply-chain-attack-to-north-korean-hackers-sapph?utm_source=mastodon&utm_medium=social

#SapphireSleet #NorthKoreanHackers #SupplyChain #MastraAi #Npm

Microsoft attributes Mastra AI supply chain attack to North Korean hackers Sapphire Sleet

Learn how North Korean hackers Sapphire Sleet launched a supply chain attack on Mastra AI, and find out how to protect your organization from similar threats now.

OSINTSights

North Korean Hackers Exploit Developer Tools in Malware Campaigns

North Korean hackers have launched a sneaky malware campaign, tricking victims into executing cross-platform malware for macOS, Linux, and Windows through malicious scripts hidden in GitHub repositories. Their latest tactic, dubbed UNK_DeadDrop, uses recruitment lures to deliver self-running code to over 75% of…

https://osintsights.com/north-korean-hackers-exploit-developer-tools-in-malware-campaigns?utm_source=mastodon&utm_medium=social

#NorthKoreanHackers #ContagiousInterview #FamousChollima #Hexagonalrodent #VoidDokkaebi

North Korean Hackers Exploit Developer Tools in Malware Campaigns

Learn how North Korean hackers exploit developer tools in malware campaigns and protect your organization from threats like UNK_DeadDrop, Contagious Interview now.

OSINTSights

North Korean Hackers Infiltrate Android Games to Spy on Defectors

Security researchers at Eset stumbled upon a sneaky plot by North Korean hackers, who infiltrated popular Android games to spy on defectors by hiding a backdoor called BirdCall in the apps. The malicious code was cleverly disguised in game files available for download on a regional gaming platform's official website.

https://osintsights.com/north-korean-hackers-infiltrate-android-games-to-spy-on-defectors?utm_source=mastodon&utm_medium=social

#NorthKoreanHackers #AndroidMalware #SupplyChain #Apt #EmergingThreats

North Korean Hackers Infiltrate Android Games to Spy on Defectors

Learn how North Korean hackers infiltrate Android games to spy on defectors. Discover the tactics used and protect yourself now from cyber threats today.

OSINTSights

North Korean Hackers Exploit Crypto Firms with AI-Driven Zoom Lures

North Korean hackers launched a massive spear-phishing campaign, targeting over 100 crypto organizations worldwide with cleverly crafted Zoom lures and AI-generated deepfakes. They used fake calendar invites and typosquatted meeting links to gain access and exfiltrate sensitive data in a matter of minutes.

https://osintsights.com/north-korean-hackers-exploit-crypto-firms-with-ai-driven-zoom-lures?utm_source=mastodon&utm_medium=social

#NorthKoreanHackers #Cryptocurrency #AidrivenAttacks #Spearphishing #ZoomExploits

North Korean Hackers Exploit Crypto Firms with AI-Driven Zoom Lures

Learn how North Korean hackers exploit crypto firms with AI-driven Zoom lures, and protect your organization from similar attacks - read the expert analysis now.

OSINTSights

North Korean Hackers Exploit Fake Zoom Meetings to Target Crypto Executives

North Korean hackers are using a sneaky tactic to target crypto executives: they pose as legitimate meeting attendees, harvesting video and audio to make future scams more convincing. They start by sending Calendly invites for fake catch-up meetings, then swap the link with a fake Zoom or Teams URL to…

https://osintsights.com/north-korean-hackers-exploit-fake-zoom-meetings-to-target-crypto-executives?utm_source=mastodon&utm_medium=social

#NorthKoreanHackers #CryptoExecutives #FakeZoomMeetings #SocialEngineering #Cryptocurrency

North Korean Hackers Exploit Fake Zoom Meetings to Target Crypto Executives

Learn how North Korean hackers exploit fake Zoom meetings to target crypto executives and discover ways to protect yourself from this social engineering scam now.

OSINTSights

North Korean Hackers Expand Malicious Package Reach Across Multiple Coding Ecosystems

Beware of the Trojan horse in your code: North Korean hackers have quietly infiltrated multiple package ecosystems, publishing around 1,700 malicious packages that masquerade as legitimate developer tools but act as malware loaders. This sneaky campaign, linked to the Contagious Interview group, puts…

https://osintsights.com/north-korean-hackers-expand-malicious-package-reach-across-multiple-coding-ecosy?utm_source=mastodon&utm_medium=social

#NorthKoreanHackers #ContagiousInterview #MalwareOperations #PackageEcosystem #Npm

North Korean Hackers Expand Malicious Package Reach Across Multiple Coding Ecosystems

North Korean hackers expand malicious package reach across coding ecosystems, infecting thousands. Learn how to protect your projects now and stay safe from Contagious Interview's malware loaders.

OSINTSights
North Korean Hackers Abuse VS Code Auto-Run Tasks to Deploy StoatWaffle Malware

North Korean hackers exploit VS Code tasks.json auto-run since Dec 2025 to deploy StoatWaffle malware, stealing data and enabling remote control.

The Hacker News
North Korean Hackers Deploy BeaverTail–OtterCookie Combo for Keylogging Attacks

Researchers at Cisco Talos have uncovered a sophisticated campaign by the Famous Chollima subgroup of Lazarus, wherein attackers deploy blended JavaScript tools.

GBHackers Security | #1 Globally Trusted Cyber Security News Platform

North Korean hackers are taking stealth to a new level: embedding malware into blockchain smart contracts and tricking devs with fake job interviews. Are we ready for a world where your next code review could be a trap?

https://thedefendopsdiaries.com/north-korean-hackers-leverage-etherhiding-malware-distribution-via-blockchain-smart-contracts/

#etherhiding
#northkoreanhackers
#blockchainsecurity
#malwaredistribution
#smartcontracts
#cyberthreats
#socialengineering
#infosec

North Korean Hackers Target Web3 with Nim Malware and Use ClickFix in BabyShark Campaign

North Korean cyber group targets Web3 businesses with Nim-based malware, exploiting AppleScript and Telegram for persistent attacks.

The Hacker News