North Korean Blamed for $290m KelpDAO Crypto Heist
2026-04-21T08:52:15Z•d735df160dc6b5c5ac9de03f53fbe6054c2b89c4ba02b66b3b70128c6b5f2a05
AI in vulnerability researchAPK malformationCVE-2024-3721CVE-2026-33032DDoS-for-hire takedownDLL sideloadingDVR command injectionFormBookJavaScript obfuscationKelpDAOLazarus GroupMCP protocolMiraiNVD policy changeOT/ICSTBK DVRZionSiphonadware AV-killingcryptocurrency theftmailbox rule abusenginx-uiransomware
What happened
A broad set of high-impact cyber incidents and trends: a $290M crypto heist attributed to North Korea’s Lazarus Group (KelpDAO), active exploitation of critical flaws (nginx-ui MCP authentication bypass CVE-2026-33032 with CVSS 9.8; Mirai-based campaigns exploiting CVE-2024-3721 in TBK DVRs), and multiple advanced malware campaigns (ZionSiphon targeting water OT/ICS, Formbook using DLL side-loading and JS obfuscation, APK malformation in Android samples). The feed also highlights major ransomware activity against automotive and healthcare sectors, law enforcement takedowns of DDoS-for-hire and
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- d735df160dc6b5c5ac9de03f53fbe6054c2b89c4ba02b66b3b70128c6b5f2a05
- Enrichment time
- 2026-04-21T08:52:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.