North Korean Blamed for $290m KelpDAO Crypto Heist

2026-04-21T08:52:15Zd735df160dc6b5c5ac9de03f53fbe6054c2b89c4ba02b66b3b70128c6b5f2a05
AI in vulnerability researchAPK malformationCVE-2024-3721CVE-2026-33032DDoS-for-hire takedownDLL sideloadingDVR command injectionFormBookJavaScript obfuscationKelpDAOLazarus GroupMCP protocolMiraiNVD policy changeOT/ICSTBK DVRZionSiphonadware AV-killingcryptocurrency theftmailbox rule abusenginx-uiransomware

What happened

A broad set of high-impact cyber incidents and trends: a $290M crypto heist attributed to North Korea’s Lazarus Group (KelpDAO), active exploitation of critical flaws (nginx-ui MCP authentication bypass CVE-2026-33032 with CVSS 9.8; Mirai-based campaigns exploiting CVE-2024-3721 in TBK DVRs), and multiple advanced malware campaigns (ZionSiphon targeting water OT/ICS, Formbook using DLL side-loading and JS obfuscation, APK malformation in Android samples). The feed also highlights major ransomware activity against automotive and healthcare sectors, law enforcement takedowns of DDoS-for-hire and

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
d735df160dc6b5c5ac9de03f53fbe6054c2b89c4ba02b66b3b70128c6b5f2a05
Enrichment time
2026-04-21T08:52:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · North Korean Blamed for $290m KelpDAO Crypto Heist · Baitaphish