North Korean Hacker Lands Remote IT Job, Caught After VPN Slip
2026-03-23T20:51:44Z•affd186b56231f11888050d385b26e6058c94146e4dcf06d2d7234f93ecf6210
AisuruAstraZenecaCSAMDDoSJackSkidJavaScriptKimWolfLAPSUS$MossadNorth KoreaVPN slipWindows malwareWindsurf IDEZoom scambotnetcloud configcredentialsdark webdata breachlaw enforcement takedownmalicious extension」「Solana」「credential theft」「SpyCloud」「non‑hummalwarenation-stateremote recruitmentsource code leak
What happened
A batch of mid-March 2026 incidents and research: LevelBlue details a suspected North Korean operative who obtained a remote IT role to fund weapons programs and was exposed after a VPN slip; law enforcement dismantled a one-person China-run dark web network hosting ~373,000 CSAM sites; an international crackdown disrupted four major DDoS botnets (Aisuru, KimWolf, JackSkid, Mossad); LAPSUS$ claims an AstraZeneca breach offering source code, credentials and cloud configs; Sublime Security reports a JavaScript-based fake Zoom invite scam delivering Windows malware; Bitdefender finds a malicious
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- affd186b56231f11888050d385b26e6058c94146e4dcf06d2d7234f93ecf6210
- Enrichment time
- 2026-03-23T20:51:44Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.