ZeroHour

Search: “kimsuky”

36 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

Rapid7 uncovered a DPRK-linked Linux toolkit using a HAProxy-embedded ted backdoor, SSH keylogger, and curlRAT against South Korean media and automotive firms.

Rapid7 Labs identified a previously undocumented framework attributed with medium confidence to DPRK actors, targeting South Korean automotive and media organizations likely since early 2025. The toolkit embeds a backdoor compiled into HAProxy 2.8.12 using its filter API, plus trojanized crond, agetty, atd, sshd, and polkitd, an SSH keylogger storing credentials under /var/lib/sshd/, and a curl-based RAT with a watchdog thread. It enables remote command execution, malicious script injection into served webpages (a watering-hole loop), credential harvesting, and long-term surveillance. Hardcoded C2s are associated with APT37 via ThreatFox, and exposed groupware portals and mail servers align with Kimsuky tradecraft; the initial access vector and any CVE remain unconfirmed.

Rapid7 Blog · 12d agoThreat actor in the wild1

Security Affairs newsletter Round 590 by Pierluigi Paganini

Weekly Security Affairs newsletter roundup aggregating top cybercrime, malware, APT and AI security stories including ExfilSquad, Kimwolf v7 and Kimsuky AI use.

This is the Round 590 weekly newsletter from Security Affairs, linking to the week's major stories rather than reporting a single incident. Headlines include ExfilSquad extortion, a 7.3M chess.com record leak, Kimwolf botnet v7, SharePoint exploitation after a public PoC, Kimsuky integrating AI, and China-linked autonomous-style attacks. It is a digest and promotional item with no standalone technical details.

Security Affairs · Aug 16, 2026Industry

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

Rapid7 found a new backdoor, ted, compiled into trojanized HAProxy at two South Korean organizations, with medium-confidence attribution to North Korean actors.

Rapid7 documented a previously undocumented Linux toolkit named ted compiled into the HAProxy load balancer binaries of two South Korean organizations in the automotive and media sectors. The implant intercepts web traffic, serves altered pages only to filtered visitors, and hides C2 exchanges from backend logs and HAProxy statistics; a companion RAT, curlRAT, beacons on a default 12-hour schedule. The toolkit also trojanizes crond, sshd, agetty, atd, and polkitd binaries and sanitizes logs and bash history. Rapid7 attributes the activity with medium confidence to North Korean state-sponsored actors, with domain infrastructure overlapping APT37 listings in maltrail and delivery resembling the Operation SyncHole campaign.

The Hacker News · 12d agoThreat actor in the wild

Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems

Check Point identifies Noodle RAT as a distinct cross-platform Windows/Linux backdoor used by Chinese-speaking actors against Asia-Pacific organizations since 2016.

Check Point assesses Noodle RAT, also known as ANGRYREBEL, as a distinct backdoor family rather than a variant of Gh0st RAT or Rekoobe, with separate Windows (Win.NOODLERAT) and Linux (Linux.NOODLERAT) variants sharing a common command-and-control design. The Windows implant runs filelessly via shellcode with loaders like MULTIDROP and MICROLOAD, while the Linux variant provides reverse shells, file management, and SOCKS tunneling after exploitation or web-shell placement on exposed servers. Groups including Iron Tiger, Calypso APT, Rocke, and Cloud Snooper have deployed it against organizations in Thailand, India, Japan, Malaysia, and Taiwan. Check Point released sample hashes and C2 IP indicators alongside the analysis.

Cyber Security News · 8h agoMalware in the wild 2 sources

Insights into Suspected DPRK Workers

Huntress details incidents involving suspected DPRK remote workers (Famous Chollima) in partner environments and shares detection indicators.

Huntress analyzed several incidents involving suspected North Korean remote workers, associated with the activity cluster known as Famous Chollima. The report describes indicators defenders can use to detect and prevent DPRK worker infiltration in customer environments. The scheme centers on operatives obtaining remote jobs at Western companies under assumed identities.

Huntress · 21d agoThreat actor in the wild

North Korea-linked IT Workers Are Getting Hired Inside Western Companies

Huntress documented five DPRK-linked FAMOUS CHOLLIMA workers hired by Western companies in 2026 using fake identities, proxies and laptop farms.

Huntress published an investigation of five confirmed 2026 cases of North Korea-linked IT workers, tracked as FAMOUS CHOLLIMA, obtaining remote jobs at legitimate companies in IT, sales, marketing and healthcare. The workers use stolen or fabricated identity documents, VPNs and proxy services, and some were caught using PiKVM hardware-level control, travel routers and laptop farms to mask their true location. Detection relied on document forensics, behavioral anomalies and indicators like identical typo artifacts in electricity bills rather than network intrusions.

Security Affairs · 15d agoThreat actor in the wild

KlueセキュリティインシデントとRecorded Futureへの影響

Recorded Future disclosed a Klue incident that exposed some Salesforce business data, including contacts and emails, via a compromised OAuth token.

Recorded Future disclosed that unauthorized activity in marketing vendor Klue's integration layer, starting June 12, 2026 and contained the same day, affected some of its Salesforce data through a compromised OAuth token in the Salesforce-Klue integration. Impacted fields are limited to business data such as customer contact names, email addresses, and possibly business contract information. No evidence indicates Recorded Future's core platform, Intelligence Graph, internal databases, or customer platform data were accessed. The company revoked all relevant OAuth tokens, coordinated with Salesforce and law enforcement, and began reviewing all third-party Salesforce integrations.

Recorded Future · Aug 12, 2026Data breach

Moonshot serves Claude instead of Kimi and collects exchanges for model training

Moonshot AI reportedly served users Anthropic's Claude instead of its own Kimi model and collected the exchanges for model training.

A Hacker News post claims Moonshot AI served user requests with Anthropic's Claude rather than its in-house Kimi model, and stored those exchanges to train future models. The item is a social media link with no technical details, drawing 42 points and 31 comments. No confirmation from Moonshot or Anthropic is included in the source text.

Hacker News · AIupdated · 9h agofirst · 5d agoAI industry 18 sourcesHN 42↑ · 31 comments1

Risky Bulletin: Expired cards can be used for new transactions

Researchers show expired Visa contactless cards can be revived via NFC man-in-the-middle relay to run fraudulent transactions; roundup also covers major breaches.

University of Massachusetts Amherst researchers built an NFC man-in-the-middle rig that updates a card's expiration date in transit and relays the modified payment to POS terminals, reviving expired contactless cards; Visa terminals and the backends of all five banks studied failed to catch the manipulation. The same roundup reports Iranian hackers shut down a small UK power plant for four days, Lazarus breached South Korea's Presidential Office as part of a campaign exceeding 100 victims, and French telecom SFR suffered a breach affecting over 2.1 million customers.

Risky Business News · 23d agoResearch1

Kimi K3 (2.8T) at 1 token/s on a MacBook Pro, streamed from four SSDs

A GitHub project streams Moonshot's 2.8T-parameter Kimi K3 from four SSDs to run at 1 token/s on a MacBook Pro.

A GitHub repository (argonautlabsai/deltafin) demonstrates running Moonshot AI's Kimi K3, a 2.8-trillion-parameter model, on a MacBook Pro by streaming its weights from four SSDs at 1 token per second. The project drew 55 points and 22 comments on Hacker News, highlighting consumer-hardware inference for extremely large models.

Risky Bulletin: BEC campaign steals €35 million from French notaries

Hackers stole over €35 million from 500+ French notary offices in a four-year BEC campaign; ANSSI spent two years helping evict the attackers.

A business email compromise campaign breached more than 500 French notary offices — about 7% of all French notaries per the Conseil Supérieur du Notariat — over four years, stealing more than €35 million by phishing initial access and silently modifying wire transfer details. France's cybersecurity agency ANSSI worked for two years behind the scenes to help notaries remove the persistent attackers, who had deep access; officials also feared hackers could issue fake notarized acts such as marriage certificates or forged real estate deals. No forged documents have been found so far, but notaries have added two-factor authentication and in-person requirements for banking details, and banks added extra checks in 2024. The newsletter also notes other incidents, including a $320 million Bitcoin extraction from Blockstream's Liquid Network and a JetBrains Cadence breach via TeamCity servers.

Risky Business News · 9d agoPhishing & fraud in the wild1

PurpleDelta's Fraudulent Employment Operations

Recorded Future details North Korean cluster PurpleDelta using AI-generated personas and ChatGPT assistants to infiltrate companies via fraudulent employment.

Recorded Future profiles PurpleDelta, a North Korean IT worker threat cluster, in a new research report. The group uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to obtain employment at target organizations and operate covertly. The report includes key indicators of compromise and recommended mitigation strategies for defenders.

Recorded Future · 29d agoThreat actor

Hackers Use Claude and GPT-Powered Tools to Help Breach Government and Financial Networks

Unit 42 links two Latin America campaigns where operators used Claude and GPT-4.1 during intrusions against government and financial targets.

Palo Alto Networks Unit 42 identified two activity clusters, CL-CRI-1131 and CL-CRI-1163, tied by shared SOCKS5 relay infrastructure and use of large language models during operations. The Mexican cluster targeted a transportation organization, federal ministries and water utilities in Mexico and Ecuador, while the Brazilian cluster used resume-themed phishing, custom remote-access Trojans and SockTz SOCKS5 tunneling against financial organizations. An exposed self-hosted NextChat interface on attacker infrastructure led researchers to assess operators used Claude and GPT-4.1 to generate workaround scripts and troubleshoot execution failures. Unit 42 noted AI reduced time needed to troubleshoot intrusions after initial access, rather than replacing the attacker.

Cyber Security News · 6d agoThreat actor in the wild 2 sources1

Red Flags That Expose Fake North Korean IT Workers

Researchers outline red flags for spotting North Korean operatives posing as remote IT workers as their tactics improve.

Dark Reading describes indicators that help organizations identify North Korean operatives working undercover as IT workers. Researchers say these operatives are improving their tactics, but detection methods still exist. Catching them early helps employers avoid infiltration, data theft, and damage.

Dark Reading · 21d agoPhishing & fraud

Critical ScreenConnect flaw now actively exploited in attacks

CISA confirms active exploitation of critical ConnectWise ScreenConnect flaw CVE-2026-84869, ordering federal agencies to mitigate within three days.

ConnectWise's ScreenConnect flaw CVE-2026-84869, an improper privilege management and missing authorization bug, lets attackers with basic privileges transfer or execute files through active remote sessions in low-complexity attacks without user interaction. It is patched in ScreenConnect 26.6.5; CISA added it to the KEV catalog and ordered US federal agencies to secure systems within three days. Shadowserver tracks over 1,000 unpatched exposed instances, mostly in North America (758) and Europe (180). This is the fourth actively exploited ScreenConnect flaw since 2024; earlier issues were abused by Kimsuky and ransomware gangs.

BleepingComputerupdated · 7h agofirst · 11h agoExploit / PoC in the wild 4 sourcesCVE-2026-84869CVE-2024-1709CVE-2025-3935+1 CVEs1

ConnectWise warns of new ScreenConnect flaw without patch

ConnectWise warns of an unpatched ScreenConnect flaw affecting file transfer in support sessions and shares interim mitigations for MSPs.

ConnectWise disclosed a new ScreenConnect Remote Access vulnerability affecting file transfer behavior in both cloud and on-premises deployments; no CVE ID or patch is available yet, with a fix planned later this week. The vendor published temporary mitigation steps that remove TransferFiles permissions from session groups across all roles. Shadowserver tracks nearly 6,000 internet-exposed ScreenConnect instances. Previous ScreenConnect flaws, including CVE-2024-1709, were exploited by ransomware gangs and North Korea's Kimsuky, and three ScreenConnect vulnerabilities are on CISA's actively exploited catalog.

North Korea-linked Hackers Hide a Backdoor Inside HAProxy

Rapid7 reports North Korea-linked hackers implanted a backdoor compiled into HAProxy at South Korean automotive and media firms, enabling covert C2 and credential theft.

Rapid7 documented a previously undocumented Linux toolkit hitting South Korean automotive and media organizations, centered on a backdoor compiled directly into victims' HAProxy 2.8.12. The 'ted backdoor' uses HAProxy's native filter API to intercept HTTP traffic, receive C2 commands hidden in requests to a fake image path, and erase all traces from logs and counters; the toolkit also trojanizes crond, agetty, atd, sshd, and polkitd, adds an SSH keylogger, and runs curlRAT with virtualization checks. It can inject scripts or replace page content for selected victims, turning the load balancer into a watering hole. Attribution sits at medium confidence toward North Korean state actors, with overlaps to APT37-linked infrastructure and a concurrent Lazarus campaign; the campaign's command domains have since gone dark.

Security Affairs · 8d agoThreat actor in the wild

North Korean remote workers are broadening their job hunt beyond IT

Huntress links suspected North Korean remote workers to sales, marketing, and healthcare jobs using stolen identities, VPNs, proxies, and KVM hardware.

Huntress investigations identified suspected DPRK remote workers hired beyond IT in sales, marketing, and healthcare/financial organizations, sometimes actually performing the work they were hired for. Fraudulent documents included passports from the same city issued one day apart, ID cards with identical validity dates, and electricity bills built from the same online template with matching typos. A financial-services case found a PiKVM and Guermok USB capture card on a new hire's laptop within hours of delivery, suggesting a laptop farm, and another hire used a police mugshot with the photo digitally swapped. Researchers urge rigorous background checks and identity verification at the interview stage.

Help Net Security · 19d agoPhishing & fraud in the wild

RelateAnything: Real-Time Open-Vocabulary Relation Prediction From Any Inputs

RelateAnything is a 53M-parameter open-vocabulary relation prediction model running at 20 ms/frame, with 2.3-3.5x higher mean recall than comparable open-vocabulary methods.

RelateAnything predicts scored relations between image regions using any predicate vocabulary supplied at inference as text embeddings, with object labels never required as input, so region sources can change without retraining. Training covers 19,103 predicates using positive-unlabeled supervision; the authors release RA-4M (474k images, 4.3M geometrically verified relations over 10,102 free-text predicates) and the OV-SGG-Bench evaluation suite. The 53M-parameter model runs at 20 ms/frame and achieves 2.3-3.5x the mean recall of the strongest comparable open-vocabulary method across cross-dataset and zero-shot benchmarks. Model, corpus, and benchmark are public.

Hugging Face daily papers · 6d agoAI research1

North Korean Hackers Deploy New Linux Espionage Toolkit

Rapid7 says North Korea-aligned actors use a new Linux espionage toolkit (ted HAProxy backdoor, CurlRAT) against South Korean automotive and media targets.

Rapid7 reports a stealthy Linux framework comprising a custom HAProxy backdoor ('ted'), trojanized system binaries (agetty, atd, crond, polkitd, sshd), an SSH keylogger, and CurlRAT that polls C&C every 12 hours. Initial access came via a Groupware login portal flaw, with credential harvesting enabling lateral movement to internal systems. The toolkit supports long-term surveillance, HTTP traffic interception/injection, and drive-by downloads, likely in use since late 2024. Infrastructure and artifacts overlap Operation SyncHole, suggesting Lazarus or APT37 involvement.

SecurityWeek · 9d agoThreat actor in the wild1

Not just Korea: Google leaked identifying info for sex crime victims across the world

Google exposed identifying information of sex crime victims who filed image-removal requests worldwide, not only in Korea, the Hankyoreh confirmed.

The Hankyoreh, reporting by Shin Da-eun and Park Kang-su, confirmed that Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images had their private information exposed online. The leak affected victims across the world, compounding harm to a highly vulnerable population. One quoted victim described photos taken when they were a minor being distributed without consent.

DataBreaches.net · 4d agoData breach

NCP-ArchPreview Technical Report: Moving towards Latent Space Language Models through Next Concept Prediction

An 8.9B-parameter latent-space language model using next-concept prediction matches OLMo-3-7B pretraining loss with only 51.3% of the training tokens.

NCP-ArchPreview augments next-token prediction with Next Concept Prediction over a product-quantized concept vocabulary built from hidden states, trained jointly end-to-end. The 8.9B model was trained on 5.73T tokens from the Dolma-3 dataset, the largest latent-space language model demonstration to date. It consumes 51.3% of the tokens to reach OLMo-3-7B's final pretraining loss and outperforms it by 2.45 points on the downstream macro-average, including a 5.99-point GSM8K gain. The learned latent space also enables lightweight domain adaptation via a 17M-parameter VQ module and improves speculative drafting accepted length by 4.17%.

Hugging Face daily papers · 8d agoAI research1

Robust Coverless Linguistic Steganography via Sentence Embedding Space with Global Resynchronization

Researchers propose a coverless steganographic framework encoding messages as hierarchical clustering paths in sentence embedding space with a Global Resynchronization Mechanism for robustness.

An arXiv paper proposes encoding secret messages as hierarchical clustering paths in the sentence embedding space rather than token space, improving decoding stability against word- and sentence-level textual perturbations. A Global Resynchronization Mechanism (GRM) reframes variable-length bitstreams as discrete symbols anchored to semantic subspaces to prevent bit-slippage. Experiments show substantial robustness improvements while maintaining embedding capacity and resistance to statistical analysis.

arXiv cs.CR · 12d agoResearch

Kimwolf v7 Hides DDoS Traffic Behind Chrome Fingerprints and Ethereum

Unit 42 details Kimwolf v7, an Android TV botnet upgrade using HTTP/2 Chrome-fingerprint DDoS floods and Ethereum ENS-based C2 across 1.8M+ infected devices.

Palo Alto Networks Unit 42 identified Kimwolf v7 on February 3, 2026, an upgrade to an Android TV botnet active since August 2025 and linked to the AISURU botnet, which has infected over 1.8 million devices. The new version adds an HTTP/2-based DDoS flood that mimics full Chrome browser fingerprints, consolidates 43 attack commands into 15 methods covering layers 3-7, and resolves C2 addresses via Ethereum Name Service using five hard-coded public blockchain RPC endpoints, backed by a Tor hidden service and a local proxy on 127.0.0.1:23075. It spreads through residential proxies to Android TV boxes with ADB enabled on port 5555 and masquerades as netd_service. The botnet is associated with the record 31.4 Tbps DDoS attack in November 2025.

Security Affairs · Aug 12, 2026Malware in the wild

DianShi-RxnDB: A Large-Scale, Fine-Grained Organic Reaction Data Platform Built via a Fully Automated Pipeline for Researchers and AI Agents

Researchers release DianShi-RxnDB, a database of roughly 24 million organic reaction instances extracted automatically from USPTO and EPO patents since 1976.

DianShi-RxnDB is built by a fully automated pipeline integrating patent text, images, and reaction schemes, yielding about 24 million reaction instances, of which 14.8 million (61.7%) pass automated qualification checks. Manual evaluation of 1,300 sampled instances showed 92.95% field-level accuracy, and comparisons with Pistachio found advantages in deduplicated record counts and granularity. The platform offers a web research workbench and a Model Context Protocol (MCP) service enabling AI agents to perform composable structured retrieval.

Hugging Face daily papers · 11d agoAI research

NOKKI Almost Ties the Knot with DOGCALL: Reaper Group Uses New Malware to Deploy RAT

Unit 42 links NOKKI malware to North Korea's Reaper group, uncovering the Final1stspy dropper that deploys the DOGCALL RAT in politically motivated attacks.

Unit 42 analyzed the NOKKI malware family used in politically themed attacks against Russian and Cambodian speakers since July 2018. The researchers linked NOKKI to the Reaper group, publicly attributed to North Korea, whose custom DOGCALL RAT uses third-party hosting services to upload data and receive commands. A previously unreported family, Final1stspy, was found deploying DOGCALL, sharing a unique base64-to-hex deobfuscation routine with NOKKI droppers. Attacks used malicious Microsoft Word macros that download and execute payloads while opening decoy documents.

Palo Alto Unit 42 · Aug 17, 2026Malware

Akira Affiliate Crashes Ransomware After Attempting EDR Evasion

Huntress documented an Akira ransomware affiliate attack that failed after its anti-EDR tool crashed legitimate software and stopped encryption before completion.

Infosecurity Magazine reports on Huntress research into a failed Akira ransomware affiliate attack. The affiliate attempted EDR evasion using an anti-EDR tool, but the tool interfered with legitimate software on the client's system. The interference crashed the ransomware before encryption completed, sabotaging the attack; no completed encryption was reported.

Infosecurity Magazine · Aug 13, 2026Ransomware

Molecular Déjà Vu: Digit-Level Retrieval of Published Values in Frontier Language Models

Audit of 22 frontier models finds widespread verbatim retrieval of published molecular property values, with higher reasoning increasing recall of memorized numbers.

An arXiv audit tests 22 frontier LLMs across 12 molecular regression benchmarks for verbatim retrieval of published values. More than 50% of the LLMs show verbatim retrieval on five datasets, and identical experiments are flagged 89% more often at a high reasoning level than at the lowest one. Suppressing retrieval moves model prediction errors closer together in relative terms, suggesting predictive capability is not determined solely by memorized values.

arXiv cs.AI / cs.LG / cs.CL · 12d agoAI research1

Norway announces investigations into telecom Telenor’s work with Myanmar junta

Norwegian police opened crimes-against-humanity and sanctions investigations into Telenor's data handovers to Myanmar's junta, raiding its Oslo headquarters.

Norway's National Criminal Investigation Service is investigating Telenor for complicity in crimes against humanity for repeatedly handing over historical customer traffic data to Myanmar's military regime between the February 2021 coup and the March 2022 subsidiary sale. The Police Security Service is separately probing sanctions violations because the sale to M1 Group included sanctioned surveillance equipment transferred without foreign ministry permission. The subsequent resale passed historical call data of over 18 million people to junta-linked owners, and a class action on behalf of 1,200 people alleges the data enabled arrests, torture, and at least one execution.

The Record · 1d agoPolicy & legal

Multi-Vector (Late Interaction) Embedding Models with Sentence Transformers

Hugging Face details building and using multi-vector late-interaction embedding models with Sentence Transformers for retrieval workloads.

Hugging Face published a guide on multi-vector, late-interaction embedding models (ColBERT-style) supported through Sentence Transformers. The post covers how practitioners can build and use these models for retrieval and RAG pipelines. It is a developer tooling and technique write-up, not a security advisory.

Hugging Face Blog · 29d agoAI tools & infra1

XHToken/Spark-X2.5-4B-GGUF — new model trending #30 on Hugging Face

XHToken released GGUF weights of Spark-X2.5-4B, a compact model with 1M-token context and 200+ language support, under Apache 2.0.

The Hugging Face repository provides BF16 GGUF conversions of Spark-X2.5-4B, a compact general-purpose language model for conversation, writing, translation, reasoning, coding, tool use, and agentic workflows. The model uses a hybrid attention architecture, supports a native context length up to 1M tokens, and covers more than 200 languages. Local inference is supported through Ollama and LM Studio via an XHToken llama.cpp fork, with a --think=false flag to disable thinking mode for faster responses. Released under Apache License 2.0; it was trending #30 on Hugging Face at publication.

Hugging Face trending models · 19d agoModel release

Leaked Russian Cyber-Operations Training Materials

Leaked Bauman university records reveal a formalized Russian pipeline training GRU cyber personnel, linking a graduate to Sandworm's Military Unit 74455.

Leaked training materials from Bauman university describe a force-generation mechanism feeding graduates into General Staff components, including the GRU and directorates responsible for protected communications, cryptography and information security. A 2024 graduate of Department No. 4, Aleksei Kondrashov, was linked to Military Unit 74455, the GRU unit known as Sandworm, which conducted destructive attacks including the 2017 NotPetya attack. Researchers say the leak shows Russian cyber capability is institutionally sustained through recruitment pipelines beyond the familiar APT28 and Sandworm brand names.

Schneier on Security · 15d agoThreat actor