https://radar.securityalliance.org/content/images/2025/11/intel-tag-3.png

SEAL Intel

7 posts

Advisory on DPRK (UNC1069) Fake Microsoft Teams and Zoom calls

Advisory on DPRK (UNC1069) Fake Microsoft Teams and Zoom calls

Following a recent axios npm package compromise, DPRK (UNC1069) is expanding beyond the crypto sector - we are publishing 164 IOCs and detailing their currently active social engineering approaches.

VS Code Tasks Abuse by Contagious Interview (DPRK)

VS Code Tasks Abuse by Contagious Interview (DPRK)

Technical dive into North Korean VS Code Abuse tactics used for Contagious Interview. DPRK IT Workers trail included.

PSA: Fake Telegram Support Channels (Drainers)

PSA: Fake Telegram Support Channels (Drainers)

Uncovering a massive crypto drainer spreading vector through the impersonation of thousands of official protocol support channels on Telegram.

From North Korean IT Workers to IT recruiters

From North Korean IT Workers to IT recruiters

The ongoing monitoring of DPRK IT workers' networks reveals the pivot from remote "workers" to "recruiters" with the goal of scaling operations.

X (Twitter) Phishing Account Takeovers

X (Twitter) Phishing Account Takeovers

Examples of recent X.com phishing campaigns leading to account's takeover.

The State of Drainers Vol. 1

The State of Drainers Vol. 1

Your guide to the ever-evolving tactics of crypto drainer campaigns.

Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Your link has expired. Please request a new one.
Great! You've successfully signed up.
Great! You've successfully signed up.
Welcome back! You've successfully signed in.
Success! You now have access to additional content.