DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

DeceptiveDevelopment is a North Korea-aligned group using sophisticated social engineering—fake recruiter profiles and the ClickFix technique—to deliver multiplatform malware like BeaverTail, InvisibleFerret, WeaselStore, TsunamiKit, Tropidoor, and AkdoorTea targeting developers and crypto-related projects. Research links their operations to North Korean IT worker fraud campaigns (WageMole), showing shared tools, stolen identities, and operational overlap between malware-driven campaigns and employment-fraud schemes. #DeceptiveDevelopment #TsunamiKit

Read More
North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers

This report details a North Korea-linked campaign called Contagious Interview, which uses multi-platform malware and social engineering tactics to target cryptocurrency developers globally. The campaign involves fake job offers and malicious programming exercises to deliver malware like BeaverTail, WeaselStore, Tropidoor, and AkdoorTea, linked to Lazarus Group tools. #ContagiousInterview #LazarusGroup…

Read More
DPDP Rules Week: The Clock Starts Ticking, as India’s Privacy Regime Shapes-Up

This article discusses India’s evolving Digital Personal Data Protection (DPDP) Act 2023 and its implications for breach management, enforcement, and compliance. It emphasizes the importance of rapid detection, continuous monitoring, and proactive measures to meet the regulatory timelines and avoid hefty penalties. #DPDP #CyberBreaches…

Read More
Alleged data sale of Ministry of Education, Research and Technology Indonesia

An alleged data sale involves over 20 million records from Indonesia’s Ministry of Education, Research and Technology, hosted at kemdikbud.go.id. The seller claims the dataset includes sensitive information such as confidential letters and financial records, with the breach reportedly occurring on August 18, 2025. #KemdikbudData #IndonesiaDataBreach…

Read More
From MUSE to Manual: Cyberattack Analysis on European Airport Operations

On 19–20 September 2025, multiple major European airports (Heathrow, Brussels, Berlin) experienced severe disruptions to check-in, boarding, and baggage systems after an attack on Collins Aerospace’s MUSE platform, forcing manual operations, delays, and cancellations. CYFIRMA assesses Alixsec, Scattered Spider, and Rhysida as plausible actors based on prior targeting and operational history. #CollinsAerospace #MUSE #Alixsec #Rhysida

Read More
Dark Web Profile: Dire Wolf Ransomware

Dire Wolf surfaced in May 2025 as a financially motivated ransomware group that rapidly claimed dozens of victims across Asia, Europe, and North America using a double-extortion model and a Tor leak site for pressure. The group uses a Go-based, UPX-packed payload that encrypts files with ChaCha20/Curve25519, leaves a HowToRecoveryFiles.txt ransom note, and marks files with the .Dire Wolf extension. #DireWolf #HowToRecoveryFiles.txt

Read More