A Fake DeFi Startup Exposed How North Korean IT Workers Get Hired
Researchers built a shell company, ran a full hiring pipeline, and let sandboxed 'employees' walk straight into a monitored environment — capturing the tooling behind DPRK employment fraud in granular detail.
Bauman University Leak Exposes Russia's GRU Cyber-Operator Pipeline
A roughly 1.8GB leak from a covert department at Bauman Moscow State Technical University details how the GRU recruits, vets, and routes students into units linked to APT28 and Sandworm.
OpenAI Disrupts Cambodia-Based ChatGPT Scam Network — What It Reveals
OpenAI banned accounts tied to a Cambodia-based crime network that used ChatGPT to run romance, crypto, gambling, and impersonation scams simultaneously — and to manage forced-labor recruitment behind the operation.
Unit 42's AI Malware Reality Check: 97% Never Left the Sandbox
Palo Alto Networks' Unit 42 analysed 405 AI-touched malware samples and found almost all of them were proof-of-concept or researcher submissions — but the handful that reached real endpoints show where the trend is actually heading.
MacSync Stealer: Microsoft Traces macOS Malware Through 30+ Rotating Domains
Microsoft Defender Experts mapped MacSync Stealer's infrastructure not by blocklisting domains, but by fingerprinting the behavior behind them — a lesson for anyone still treating IOC feeds as a detection strategy.
Dysphoria Botnet Moves C2 to Ethereum and Solana Name Services
After a March law-enforcement takedown of JackSkid infrastructure, the same IoT-botnet operator rebuilt around blockchain name records and infected-device relays — a design built to survive the next seizure.
Insurance Phishing Goes Real-Time: Inside the InsureOTP Kit
CTM360 has uncovered a phishing framework that no longer waits to cash in stolen logins — it hijacks insurance accounts live, relaying intercepted OTPs before they expire.