North Korean Hacker Lands Remote IT Job, Caught After VPN Slip

2026-03-23T20:51:44Zaffd186b56231f11888050d385b26e6058c94146e4dcf06d2d7234f93ecf6210
AisuruAstraZenecaCSAMDDoSJackSkidJavaScriptKimWolfLAPSUS$MossadNorth KoreaVPN slipWindows malwareWindsurf IDEZoom scambotnetcloud configcredentialsdark webdata breachlaw enforcement takedownmalicious extension」「Solana」「credential theft」「SpyCloud」「non‑hummalwarenation-stateremote recruitmentsource code leak

What happened

A batch of mid-March 2026 incidents and research: LevelBlue details a suspected North Korean operative who obtained a remote IT role to fund weapons programs and was exposed after a VPN slip; law enforcement dismantled a one-person China-run dark web network hosting ~373,000 CSAM sites; an international crackdown disrupted four major DDoS botnets (Aisuru, KimWolf, JackSkid, Mossad); LAPSUS$ claims an AstraZeneca breach offering source code, credentials and cloud configs; Sublime Security reports a JavaScript-based fake Zoom invite scam delivering Windows malware; Bitdefender finds a malicious

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
hackread
Record identifier
affd186b56231f11888050d385b26e6058c94146e4dcf06d2d7234f93ecf6210
Enrichment time
2026-03-23T20:51:44Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · North Korean Hacker Lands Remote IT Job, Caught After VPN Slip · Baitaphish