Counter-Intelligence Operation Against North Korean State-Sponsored APT Infrastructure
Security researcher Vangelis Stykas conducted an active defense operation by infiltrating the command-and-control (C2) infrastructure of North Korean state-sponsored threat actors. Through two years of persistent access to adversary servers, Stykas exfiltrated internal databases, C2 configurations, and victim lists, revealing hundreds of compromised networks worldwide. The operation uncovered a significant "visibility gap," demonstrating that current industry telemetry drastically underestimates the scale of North Korean espionage and financial theft. The breach provided direct access to the actors' custom toolsets, persistence mechanisms, and lateral movement logs across diverse sectors including finance, defense, and cryptocurrency.
The Rise of Agentic AI and the VoidLink C2 Framework
The transition to "Agentic AI" has enabled attackers to shift from AI-assisted tool use to autonomous operation, exemplified by the VoidLink C2 framework—an 88,000-line offensive suite generated by AI in under seven days. This framework and associated techniques utilize agentic configuration files for durable jailbreaks and content-borne indirect prompt injections, which saw a fivefold increase between March and May 2026. Technical impacts include the deployment of AI-generated Linux kernel rootkits and automated vishing for OTP theft, specifically targeting the Business Services sector, where high-risk GenAI interactions have reached 5.91%.
UAT-7810: Longleash Malware and Operational Relay Box ORB Infrastructure
China-nexus threat actor UAT-7810 is deploying a decentralized Operational Relay Box (ORB) infrastructure by compromising edge devices, including routers and firewalls, to obfuscate Command and Control (C2) traffic. Utilizing the "Longleash" malware, the actor achieves persistence within embedded firmware to route malicious egress through legitimate residential and corporate IP spaces. This architecture bypasses geolocation filters and IP reputation-based detection systems. Primary targets include government contractors and SMBs. Detection requires monitoring for non-standard tunneling protocols and anomalous outbound traffic originating from perimeter hardware, focusing on firmware integrity and egress filtering.
Underminr: Bypassing Security Filters via Cloudflare, Akamai, AWS CloudFront, and Fastly CDN Infrastructure
Underminr is a systemic architectural vulnerability across the world's largest Content Delivery Network (CDN) providers that enables threat actors to encapsulate malicious Command and Control (C2) traffic within trusted infrastructure. By exploiting the shared reputation of CDN edge nodes, attackers can effectively bypass domain-based filtering and IP blacklisting, rendering traditional perimeter defenses obsolete.