Signal
North korean cyber campaigns target air-gapped systems and deploy new malware
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-03-02 08:44 UTCUpdated 2026-03-03 00:29 UTC
rss
sc_media_north_korea
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.3 top sources shown
Overview
Recent cyber activities by North Korean threat actors include targeting air-gapped systems with new implants, leveraging Zoho WorkDrive in malware campaigns, and publishing malicious npm packages that extract command-and-control information.
Score total
1.26
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
- Recent disclosures reveal a surge in North Korean cyber activities.
- The tactics employed indicate a strategic shift in targeting methods.
- Increased awareness is crucial as these threats continue to evolve.
Why it matters
- These campaigns demonstrate the evolving tactics of North Korean threat actors.
- Targeting air-gapped systems poses significant risks to sensitive environments.
- The use of npm packages highlights the need for vigilance in software supply chains.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- North Korean APT targets air-gapped systems using Windows shortcut files.
- ScarCruft group leverages Zoho WorkDrive and removable media in new cyber campaign.
- North Korean hackers publish 26 npm packages hiding Pastebin C2 for cross-platform RAT.
How sources frame it
- SecurityWeek: neutral
- The Hacker News: neutral
- SC Media: neutral
This entry summarizes recent cyber activities attributed to North Korean threat actors, highlighting their tactics and targets.
All evidence
All evidence
North Korea's ScarCruft group leverages Zoho WorkDrive and removable media in new cyber campaign
SC Media · scworld.com · 2026-03-03 00:29 UTC
North Korean APT Targets Air-Gapped Systems in Recent Campaign
SecurityWeek · securityweek.com · 2026-03-02 11:46 UTC
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT
The Hacker News · thehackernews.com · 2026-03-02 08:44 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
- SC Media (1)
- SecurityWeek (1)
- The Hacker News (1)
Top origin domains (this list)
- scworld.com (1)
- securityweek.com (1)
- thehackernews.com (1)