logo

KMsec blog

ID: 4bbe082c-5e3e-5da7-8d30-832e4f5dfe26

STIX ID: identity--4bbe082c-5e3e-5da7-8d30-832e4f5dfe26

Feed Type: rss

Earliest post: 2021-08-06

Latest post: 2026-05-01

The KMsec blog is an independent cybersecurity research blog sharing deep technical analyses and threat intelligence—particularly on malware campaigns, attacker infrastructure, and OSINT investigations

01/01/2020
06/04/2026
Title Date Published Describes IncidentAuthorVisible
Parsing Google Docs HTML2026-04-24TrueTrue
Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators2026-03-17TrueTrue
First instance of PylangGhost RAT observed on npm2026-03-13TrueTrue
Novel DPRK stager using Pastebin and text steganography2026-02-26TrueTrue
Tracking DPRK operator IPs over time2026-02-22TrueTrue
DPRK tests Google Drive as a malware stager2026-02-21TrueTrue
Exposed DPRK reference malware and logs2026-02-16TrueTrue
VMWare artifacts left by a FAMOUS CHOLLIMA operator2026-02-13TrueTrue
Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign2023-03-05TrueTrue
Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign2023-03-05TrueTrue
Fingerprinting C2s with Shodan2023-01-06TrueTrue
Tracking Crimson Kingsnake2023-01-06TrueTrue
Tracking Crimson Kingsnake2023-01-06TrueTrue
Fingerprinting C2s with Shodan2023-01-06TrueTrue

1–14 of 14