Researchers published an investigation into suspected DPRK-linked cryptocurrency intrusions, outlining activity tied to crypto theft operations and the tradecraft used to compromise digital asset targets. The reporting frames the campaign as part of North Korea’s broader effort to generate revenue through cyber operations, with intrusions aimed at organizations handling cryptocurrency and related infrastructure.
Separate reporting detailed an alleged ShinyHunters breach involving the EU Europa platform, claiming the exposure of roughly 90GB of data and highlighting the potential compromise of DKIM keys and weaknesses in single sign-on (SSO) architecture. The analysis said the incident could have affected authentication and trust mechanisms tied to the platform, raising concerns about downstream abuse of exposed email-signing material and identity systems.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.