In April 2025, Huntabil.IT observed a targeted attack on a Web3 startup, attributing the incident to a DPRK threat actor group. Several reports on social media at the time described similar incidents at other Web3 and Crypto organizations.
Analysis revealed an attack chain consisting of an eclectic mix of scripts and binaries written in AppleScript, C++ and Nim. Although the early stages of the attack follow a familiar DPRK pattern using social engineering, lure scripts and fake updates, the use of Nim-compiled binaries on macOS is a more unusual choice. A report by Huntress in mid-June described a similar initial attack chain as observed by Huntabil.IT, albeit using different later stage payloads.
Read more…
Source: SentinelLABS
Sign up for the Cyber Security Review Newsletter
The latest news and insights delivered right to your inbox.
Related:
- Atomic macOS (AMOS) Stealer Activity
September 16, 2026
This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. This article presents a snapshot of indicators seen in early August 2026 and is designed to help readers better understand AMOS stealer. AMOS stealer is an information ...
- NightEagle targets Russian companies
September 16, 2026
Over the past year, Kaspersky Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on organizations in Asia. Kaspersky researchers have now identified attacks by the group targeting businesses in Russia. This post examines both known and new ...
- Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
September 16, 2026
The ShinyHunters hacking group has published hundreds of thousands of files from a Florida state database of vehicles and driver information. The hackers said they published the stolen data on its leak site “because the victim did not pay a ransom or cooperate and comply” with the hackers’ demands. The hackers said they breached the database, ...
- CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild
September 15, 2026
On September 14, 2026, Cisco published a security advisory for CVE-2026-76461, a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure ...
- Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products
September 15, 2026
Apple has addressed more than 260 CVEs across all of its operating systems, browsers, and other software products, marking the largest single patch cycle in Cupertino’s history. While this CVE count is hardly notable compared to some vendors – hello, Microsoft’s record-breaking 974 bugs disclosed earlier this month – it does set a company record for ...
- Iranian Cyber Targeting of Dissidents, Activists and Journalists
September 15, 2026
CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. Iran almost ...
