North Korean threat actors expanded beyond traditional espionage into large-scale cryptocurrency theft and intrusion campaigns, with research presented at Black Hat identifying 1,640 organizations in 57 countries touched by the activity and roughly 700 to 800 showing clearly malicious compromise. Investigators said some intrusions reached root-level access on servers and AWS accounts, while attackers also abused third-party contractors to reach government, healthcare, and private-sector victims. The activity was linked broadly to DPRK operations including Lazarus Group, which researchers said continues to pair social engineering with crypto theft and laundering to generate revenue believed to support sanctions evasion and state priorities.
Separate reporting tied the shift to specific DPRK espionage clusters now targeting crypto users and firms directly. Konni was described as moving from South Korea-focused Windows espionage to a global macOS campaign using fake recruiter or document lures, AppleScript, LaunchAgents, TCC abuse, and payloads including FileRATClient and an EggShell variant. Kimsuky was reported to have operated a fake trading platform, Tralert FX, distributing a trojanized desktop app through direct download and the Microsoft Store before deploying a customized Xeno RAT via GitLab staging; researchers said that campaign affected more than 250 victim IPs across 28 countries.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
A Bluesky account, lazarusholic.bsky.social, shared Zscaler's publication "Not Just Spies Anymore: DPRK's Espionage Actors Are Coming for Your Crypto" and linked to the HITCON 2026 SlideShare deck. The post highlighted Kimsuky, Konni, macOS, XenoRAT, and TokenPhantom.
In early 2026, a Kimsuky-linked group created the fake cryptocurrency trading platform Tralert FX and promoted it through social media and cryptocurrency forums. The operation distributed a trojanized desktop app via direct download and the Microsoft Store, ultimately deploying a customized Xeno RAT.
The HITCON 2026 presentation states that ESET independently confirmed the same September 2025 Konni campaign involving an AppleScript lure, credential theft, and the EggShell implant. This served as third-party corroboration for attribution of the macOS activity to Konni.
Starting in late 2025, the DPRK-linked Konni group began its first observed macOS campaign targeting cryptocurrency industry professionals with lures themed around OTC trades, token transfers, and Web3 payment documents. The campaign used fake document bundles, credential theft prompts, TCC abuse, persistence, and final-stage implants including FileRATClient and an EggShell variant.
At the Black Hat conference in Las Vegas, researcher Vangelis Stykas said he identified 1,640 organizations across 57 countries affected by North Korean hacker activity, with roughly 700 to 800 suffering clearly malicious intrusions. He said some victim servers and AWS accounts were compromised at the root level and that he collected five terabytes of data after infiltrating the hackers' environment.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
bsky.app
Open sourcecysecurity.news
Open sourceslideshare.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.