NorthScan

37 posts

NorthScan banner
NorthScan

NorthScan

@north_scan

Investigating North Korean IT Worker Infiltration Driven by OSINT & HUMINT | Founded by @0xfigo

◾◾◾ Katılım Mayıs 2021
38 Takip Edilen111 Takipçiler
NorthScan retweetledi
The Hacker News
The Hacker News@TheHackersNews·
⚠️ A fake job notice triggered full compromise in a Konni campaign. The attack drops EndRAT, enabling remote control, persistence, and silent data theft, then spreads via KakaoTalk messages from the victim’s account. Trusted contacts become the attack path. 🔗 Read → thehackernews.com/2026/03/konni-…
The Hacker News tweet media
English
4
37
138
37.5K
NorthScan retweetledi
NK NEWS
NK NEWS@nknewsorg·
North Korean hackers deploy arsenal of six new malware in espionage campaign cstu.io/54faca
English
2
5
9
1.1K
NorthScan retweetledi
NK NEWS
NK NEWS@nknewsorg·
North Korean hackers exploit Google advertising links to steal data cstu.io/eca240
English
0
5
5
1.2K
NorthScan retweetledi
Security Alliance
Security Alliance@_SEAL_Org·
SEAL Intel investigator Heiner (@0xfigo) delves into the ever-changing world of DPRK IT Workers. The latest report uncovers a new strategy - enhancing job fraud with a scalable model of actively recruiting outside collaborators to bypass identity checks.
English
5
6
37
3.4K
NorthScan retweetledi
NK NEWS
NK NEWS@nknewsorg·
Russian Wagner Group-linked cargo jet makes rare flight to North Korea cstu.io/9cdc24
English
5
25
58
32.8K
NorthScan retweetledi
ANY.RUN
ANY.RUN@anyrun_app·
⚠️ #Lazarus Group’s Famous Chollima uses GitHub spam, fake recruiters, and AI interview tools to slip into finance, crypto, and healthcare companies as “IT workers”. 👨‍💻 Get a rare inside view of how these operatives work, communicate, and attempt to maintain access. See how #ANYRUN helped @BirminghamCyber & @north_scan reveal and analyze the hackers' toolchain and TTPs: any.run/cybersecurity-…
English
5
24
101
10.1K
NorthScan retweetledi
Shreyas Reddy
Shreyas Reddy@shreyas_k_reddy·
Great talking to @MauroEldritch about the fascinating operation he, @north_scan and @anyrun_app carried out to dupe DPRK IT workers and expose their tools & techniques (while trolling them masterfully)! For more, check out @nknewsorg's story on their op: nknews.org/pro/share/b789…
Mauro Eldritch 🏴‍☠️@MauroEldritch

🇰🇵 I spoke with NK News about how we recorded an entire Famous Chollima operation and exposed their chats, tools, and targets. 🤝 Thanks @shreyas_k_reddy for the interview!

English
2
3
6
1.2K
NorthScan retweetledi
International Cyber Digest
International Cyber Digest@IntCyberDigest·
‼️🇰🇵 Meet North Korean recruiter 'Aaron,' who infiltrates Western companies by using AI and posing as a remote IT worker using stolen or rented identities. He was lured into a sandbox by researchers, who observed the wild APT in a controlled setting to see what he would do.
English
31
460
3.2K
650.5K
NorthScan retweetledi
BlockOSINT
BlockOSINT@0xfigo·
Glad to finally share our latest research into North Korean IT workers and their recent activity, published in collaboration with @MauroEldritch and the team at @anyrun_app Take a closer look at how these threat actors approach people, how they behave, and some of the tooling we observed.
English
2
2
8
964