Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [QUIET] · [TECHNOLOGY]
8 clusters · 32 sources · 60 days · First seen · Last updated
North Korean crypto hacking and software supply-chain ops
Overview
By August 2026, North Korean state-sponsored actors had targeted over 1,640 organizations across 57 countries. Intelligence from Proofpoint identified the ‘UNK_DeadDrop’ cluster, which targets developers via phishing campaigns using malicious Visual Studio Code extensions (VSIX) and GitHub repositories to deploy cross-platform malware. This technical exploitation is paired with a social engineering strategy where operatives use identity theft, fraudulent banking, and artificial intelligence to impersonate foreign nationals in remote work roles.
These fraudulent schemes are expanding beyond IT into healthcare, sales, and marketing. In February 2026, three North Korean workers impersonating Chinese nationals were identified at an Australian healthcare company after investigators detected suspicious VPN usage and passport anomalies. The FBI is currently investigating a North Korean national who secured remote employment with a U.S. federal agency. Todd Hemmen, deputy assistant director of the FBI’s Cyber Capabilities Branch, noted that operatives use stolen identities, fraudulent documents, and VPNs to mask their locations, sometimes utilizing US-based facilitators to receive hardware.
Financial investigations by the Royal United Services Institute (RUSI) estimate North Korea stole at least $2.8 billion in cryptocurrency between January 2024 and September 2025 to fund weapons programs. To manage these assets, Pyongyang increasingly outsources laundering to Asian criminal networks, such as ‘pig butchering’ syndicates, or sells stolen coins at a discount to third parties. This process involves mixing stolen funds with criminal proceeds and utilizing money mules in China, the Philippines, and Indonesia, alongside entities like Cambodia’s Huione Group to convert digital assets into fiat currency.
Entities
North Korea · FBI · Todd Hemmen · Huntress · Elliptic
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 6 SOURCES] North Korean‑linked hackers compromised four npm packages (typo‑crypto, debug, chalk, axios) between March 2025 and March 2026.
- [● 5 SOURCES] The attacks are attributed to a North Korean group tracked as Sapphire Sleet, UNC1069 and related aliases.
- [● 4 SOURCES] The compromised axios package receives more than 100 million weekly downloads.
- [● 2 SOURCES] The macOS campaign employed blockchain‑hosted command‑and‑control via Ethereum smart contracts (EtherHiding).
- [● 2 SOURCES] The macOS attack installed a malicious Chrome extension that drains cryptocurrency wallets.
- [● 2 SOURCES] Approximately one in ten cloud environments can be affected within two hours of a poisoned npm package update.
- [● 2 SOURCES] The fake macOS update copies a curl command to the clipboard and prompts the user to paste it into Terminal (ClickFix).
- [○ 1 SOURCE] A Rust‑based macOS malware called Gaslight embeds 38 adversarial prompt‑injection strings to evade AI triage tools.
- [○ 1 SOURCE] The campaign targets 157 cryptocurrency wallets.
Timeline
-
16 days ago
[TECHNOLOGY] 3 sourcesNorth Korea expands fraudulent job schemes into healthcare and salesNorth Korean actors are expanding fraudulent remote employment schemes into healthcare and sales to fund weapons programs, using forged identities and VPNs to bypass corporate security.
-
about 1 month ago
[TECHNOLOGY] 3 sourcesFBI investigates North Korean IT worker at US federal agencyThe FBI is investigating a North Korean IT worker who infiltrated a US federal agency using false identities, highlighting growing risks of remote-work espionage and AI-enhanced recruitment fraud.
-
about 1 month ago
[INTERNATIONAL] 2 sourcesNorth Korea uses criminal networks to launder $2.8 billion in stolen cryptoNorth Korea stole $2.8 billion in crypto between Jan 2024 and Sept 2025, increasingly using Asian criminal networks to launder the funds to finance its weapons program.
-
about 1 month ago
[TECHNOLOGY] 4 sourcesNorth Korean actors target developers and infiltrate agencies via remote workNorth Korean actors are using sophisticated phishing, AI, and identity theft to secure remote jobs and fund weapons programs, including a suspected infiltration of a U.S. federal agency.
-
about 2 months ago
[TECHNOLOGY] 10 sourcesNorth Korean Hackers Target macOS Users and Open‑Source npm PackagesNorth Korean hackers used a fake macOS update with blockchain C2 to steal crypto and deployed a malicious Chrome extension, while also compromising npm packages (typo‑crypto, debug, chalk, axios) to inject code
-
about 2 months ago
[CRIME] 5 sourcesNorth Korea arrests former military hackers accused of stealing state bank funds via cryptocurrencyNorth Korea arrested former military hackers on July 12, accusing them of breaching state banks and laundering stolen funds via cryptocurrency, though the claims are unverified.
-
about 2 months ago
[TECHNOLOGY] 6 sourcesNorth Korean Crypto Threats Spur Security Reveal and ArrestsFireblocks revealed “BitForge” crypto wallet flaws that could aid nation‑state attackers like North Korea’s Lazarus group, while North Korean officials reportedly arrested a team accused of hacking state banks
-
3 months ago
[CRIME] 2 sourcesNorth Korea-linked hackers seize $643 million in crypto, 66% of H1 global lossNorth Korean-linked hackers stole about $643 million in crypto in H1 2024, representing 66 % of the $972 million global crypto‑hacking loss, mainly from two DeFi platform breaches.
Sources
abmedia.io · b2b-cyber-security.de · brasilemfolhas.com.br · clubic.com · cointelegraph.com · countryrebel.com · crypto-news-flash.com · cryptobriefing.com · cryptopolitan.com · cybernoz.com · cyberscoop.com · cybersecuritynews.com · decrypt.co · dev.to · editorials.voa.gov · en.coin-turk.com · flagthis.com · ibtimes.co.uk · it-boltwise.de · journalducoin.com · livecoins.com.br · news-krypto.de · news.donga.com · opensourceforu.com · police.cz · securityaffairs.co · sf-encyclopedia.com · spacemoney.com.br · stv.seoul.co.kr · thehackernews.com · theregister.com · tokenpost.com
This summary has been updated 7 times: see revision history