Counter-Intelligence Operation Against North Korean State-Sponsored APT Infrastructure
Security researcher Vangelis Stykas conducted an active defense operation by infiltrating the command-and-control (C2) infrastructure of North Korean state-sponsored threat actors. Through two years of persistent access to adversary servers, Stykas exfiltrated internal databases, C2 configurations, and victim lists, revealing hundreds of compromised networks worldwide. The operation uncovered a significant "visibility gap," demonstrating that current industry telemetry drastically underestimates the scale of North Korean espionage and financial theft. The breach provided direct access to the actors' custom toolsets, persistence mechanisms, and lateral movement logs across diverse sectors including finance, defense, and cryptocurrency.
OtterCookie Infostealer: North Korean Actors Leverage SVG Steganography and npm Supply Chain Attacks
North Korean-linked threat actors are executing the "Contagious Interview" campaign, targeting developers through fraudulent recruitment. The attack utilizes SVG steganography to embed malicious payloads within graphic assets and leverages malicious npm packages with multi-layer dependency nesting to deliver the OtterCookie infostealer. The malware executes a four-stage payload to exfiltrate browser credentials, session cookies, cryptocurrency wallet data, and sensitive local files. This sophisticated approach bypasses traditional static analysis and EDR via supply chain compromise and steganographic evasion, posing a severe risk to technical workstations and developer environments.