home.social

#famouschollima — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #famouschollima, aggregated by home.social.

fetched live
  1. 📢 Faux travailleurs nord-coréens : Famous Chollima infiltre des entreprises via l'emploi frauduleux

    Cet article analyse en profondeur la menace des faux travailleurs nord-coréens, opération attribuée au groupe Famous Chollima (également suivi sous les noms UNC5267 par Mandiant/Google, Jasper Sleet par Microsoft, et associé à Wagemole)…

    📖 cyberveille : cyberveille.ch/posts/2026-09-1
    🌐 source : blog.barracuda.com/2026/09/14/
    🟡 vérification factuelle moyenne
    #FamousChollima #FauxTravailleurs #Cyberveille

  2. 📢 Chaîne de dépendances npm malveillantes ulid-xyz liée au groupe FAMOUS CHOLLIMA (DPRK)

    Cet article présente une analyse technique approfondie d'une chaîne de livraison de malware via l'écosystème npm, détectée en juin 2026 et référencée sous l'advisory MAL-2026-6672. L'attaque repose sur trois packages npm imbriqués : ioredis-xyz (Layer 1)…

    📖 cyberveille : cyberveille.ch/posts/2026-09-0
    🌐 source : safedep.io/ulid-xyz-transitive
    🟡 vérification factuelle moyenne
    #DPRK #FAMOUSCHOLLIMA #Cyberveille

  3. North Korean Hackers Exploit Developer Tools in Malware Campaigns

    North Korean hackers have launched a sneaky malware campaign, tricking victims into executing cross-platform malware for macOS, Linux, and Windows through malicious scripts hidden in GitHub repositories. Their latest tactic, dubbed UNK_DeadDrop, uses recruitment lures to deliver self-running code to over 75% of…

    osintsights.com/north-korean-h

    #NorthKoreanHackers #ContagiousInterview #FamousChollima #Hexagonalrodent #VoidDokkaebi

  4. Void Dokkaebi evolve InvisibleFerret: il malware nordcoreano ora usa Cython per sfuggire agli antivirus

    Void Dokkaebi (Famous Chollima), APT nordcoreano specializzato nel targeting di sviluppatori software, ha aggiornato il proprio infostealer InvisibleFerret compilandolo da Python a Cython. I file ora distribuiti come .pyd e .so bypassano la maggior parte delle detection tradizionali. La campagna ha compromesso oltre 750 repository GitHub e utilizza infrastruttura blockchain per rendere i C2 immuni ai takedown.

    insicurezzadigitale.com/void-d

  5. AI-Assisted Code Targets Crypto Wallets via Malicious npm Dependency

    Researchers have uncovered a sneaky malicious npm campaign, dubbed PromptMink, linked to North Korean hackers Famous Chollima, which targets crypto developers with fake utility packages that secretly steal sensitive info and funds. The campaign's clever tactics even involve an AI-assisted code commit to fly under the radar.

    osintsights.com/ai-assisted-co

    #MaliciousNpmDependency #AiassistedCode #CryptoWallets #FamousChollima #Apt37

  6. Contagious Interview diventa un worm: Void Dokkaebi trasforma 750 repository in vettori auto-propaganti contro gli sviluppatori

    Il gruppo APT nordcoreano Void Dokkaebi (Famous Chollima) ha trasformato le sue finte offerte di lavoro in un attacco supply chain capace di propagarsi automaticamente: basta aprire un repository clonato in VS Code per attivare payload nascosti in commit manipolati. A marzo 2026, Trend Micro ha mappato oltre 750 repository infetti, 500 task.json malevoli e staging C2 su Tron, Aptos e Binance Smart Chain.

    insicurezzadigitale.com/contag

  7. Watch as North Korean hackers from the #FamousChollima group are caught using AI deepfakes and stolen identities in fake job interviews to infiltrate crypto and #Web3 firms.

    Details: hackread.com/north-korean-hack

    #CyberSecurity #CyberCrime #NorthKorea #Lazarus #Scam #AI

  8. Watch out as the North Korean hackers from the #FamousChollima group are using fake job offers to spread BeaverTail and OtterCookie malware, stealing crypto and credentials in a new attack.

    Read: hackread.com/nk-famous-chollim

    #Cybersecurity #Malware #BeaverTail #OtterCookie #NorthKorea

Share on Mastodon

Enter the server where you have an account.