A North Korean state-sponsored threat actor was inadvertently exposed after a LummaC2 infostealer infection compromised a device used in the $1.4 billion Bybit cryptocurrency exchange heist. Analysis by Hudson Rock and Silent Push revealed that the infected machine, operated by a malware developer within North Korea’s cyber apparatus, contained credentials and infrastructure directly tied to the Bybit attack, including the registration of a phishing domain used in the operation. This rare insight into North Korean cyber operations highlights the shared use of development rigs, credential sets, and infrastructure among state-backed actors, providing a unique window into their methods and operational overlaps.
In parallel, Windows systems have been targeted by the advanced KimJongRAT malware, attributed to North Korean APT group Kimsuky, through phishing campaigns leveraging malicious HTA files. Attackers distribute ZIP archives containing LNK files disguised as tax notice PDFs, which, when executed, use mshta to activate the HTA file and deploy KimJongRAT. The malware is capable of exfiltrating system data, browser credentials, cryptocurrency wallet information, and messaging app accounts, with its behavior adapting based on the presence of security software like Windows Defender. These incidents underscore the ongoing sophistication and adaptability of North Korean cyber operations targeting both financial and information assets globally.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Hudson Rock, with corroboration from Silent Push, disclosed that a North Korean threat actor's machine had been compromised by LummaC2, calling it the first documented case of an infostealer infecting a North Korean operator. The exposed system reportedly contained malware development tools, VPN software, communications apps, and evidence of fake Zoom installer phishing activity.
In 2025, a North Korean state-sponsored malware developer was inadvertently infected by the LummaC2 infostealer. The compromise exposed operational details, including phishing domains, credential management activity, and links to infrastructure associated with the Bybit breach.
Reporting revealed that the KimJongRAT campaign adjusted its payloads based on whether Windows Defender was active, while stealing system data, browser storage, encryption keys, cryptocurrency wallets, and Discord and Telegram credentials. The disclosure highlighted the malware's persistence, evasion, and data-exfiltration mechanisms.
A campaign attributed to the North Korean APT group Kimsuky targeted Windows users with phishing emails posing as tax notices. The messages delivered ZIP archives containing an LNK file disguised as a PDF, which used mshta to execute a Base64-encoded HTA file and install KimJongRAT.
In February 2025, attackers linked to North Korean operations conducted a $1.4 billion breach of the Bybit cryptocurrency exchange. Later forensic analysis tied infrastructure on a compromised North Korean operator device to this heist.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.