threat-intel How QR-code phishing can slip past corporate security measures QR code phishing, known as ‘quishing,’ is rapidly becoming a significant threat, bypassing traditional email security filters and leveraging familiarity with QR codes to trick employees into accessing malicious content. Attackers are increasingly using QR codes in conjunction with social engineering tactics, including… WeLiveSecurity · Aug 17, 2026 High NOqr codephishingquishing
threat-intel Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development North Korea's Kimsuky hacking group is building an offline AI infrastructure to bolster its phishing attacks and automate malware development. Security firm Genians discovered this setup, finding tools like Ollama, GPT4A… The Hacker News · Aug 10, 2026 High KRaiphishingnorth korea
threat-intel New Kimsuky campaign compromised South Korean software vendors A new campaign by North Korean threat actor Kimsuky (APT43) targeted South Korean software vendors in 2025 and 2026, ultimately compromising their customers. The group leveraged social engineering and exploiting remote c… The Record · Jul 22, 2026 High KRnorth koreaapt43social engineering
malware Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery This report details a concerning trend in malware delivery – the evolution of ClickFix, a technique where users are tricked into running malicious code by hand. Researchers have uncovered a new API-driven approach to gen… The Hacker News · Jul 1, 2026 High RUIRNOmalwarepayloadapi
threat-intel Kimsuky Deploys HTTPSpy, Expands Arsenal with HelloDoor and VS Code Tunnels North Korean state-sponsored threat actor Kimsuky has expanded its arsenal and tactics, utilizing HTTPSpy, HelloDoor, and VS Code tunnels to target South Korean military and corporate entities between March and April 202… The Hacker News · May 29, 2026 High KRnorth koreanremote access trojansocial engineering
threat-intel ESET APT Activity Report Q4 2025–Q1 2026 ESET’s Q4 2025 – Q1 2026 APT Activity Report highlights a period of intense geopolitical activity driving advanced cyber espionage. China-aligned actors were mobilized to monitor maritime and energy developments, while I… WeLiveSecurity · May 28, 2026 High CHIRPOaptcyber espionagegeopolitics
threat-intel Kimsuky targets organizations with PebbleDash-based tools This report details the ongoing activity of the Kimsuky threat actor group, also known as APT43, who have been utilizing a PebbleDash-based malware platform to conduct targeted attacks. The group has significantly evolve… Securelist · May 14, 2026 High KRBRDEspear phishingremote access trojansouth korea