Signal

North korean cyber campaigns target air-gapped systems and deploy new malware

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-03-02 08:44 UTCUpdated 2026-03-03 00:29 UTC
rss
sc_media_north_korea
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.
3 top sources shown
Overview

Recent cyber activities by North Korean threat actors include targeting air-gapped systems with new implants, leveraging Zoho WorkDrive in malware campaigns, and publishing malicious npm packages that extract command-and-control information.

Score total
1.26
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
  • Recent disclosures reveal a surge in North Korean cyber activities.
  • The tactics employed indicate a strategic shift in targeting methods.
  • Increased awareness is crucial as these threats continue to evolve.
Why it matters
  • These campaigns demonstrate the evolving tactics of North Korean threat actors.
  • Targeting air-gapped systems poses significant risks to sensitive environments.
  • The use of npm packages highlights the need for vigilance in software supply chains.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
  • North Korean APT targets air-gapped systems using Windows shortcut files.
  • ScarCruft group leverages Zoho WorkDrive and removable media in new cyber campaign.
  • North Korean hackers publish 26 npm packages hiding Pastebin C2 for cross-platform RAT.
How sources frame it
  • SecurityWeek: neutral
  • The Hacker News: neutral
  • SC Media: neutral
This entry summarizes recent cyber activities attributed to North Korean threat actors, highlighting their tactics and targets.
All evidence
All evidence
North Korean APT Targets Air-Gapped Systems in Recent Campaign
SecurityWeek · securityweek.com · 2026-03-02 11:46 UTC
North Korean Hackers Publish 26 npm Packages Hiding Pastebin C2 for Cross-Platform RAT
The Hacker News · thehackernews.com · 2026-03-02 08:44 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
  • SC Media (1)
  • SecurityWeek (1)
  • The Hacker News (1)
Top origin domains (this list)
  • scworld.com (1)
  • securityweek.com (1)
  • thehackernews.com (1)