logo

KMsec blog

ID: 4bbe082c-5e3e-5da7-8d30-832e4f5dfe26

STIX ID: identity--4bbe082c-5e3e-5da7-8d30-832e4f5dfe26

Feed Type: rss

Earliest post: 2021-08-06

Latest post: 2026-06-10

The KMsec blog is an independent cybersecurity research blog sharing deep technical analyses and threat intelligence—particularly on malware campaigns, attacker infrastructure, and OSINT investigations

01/01/2020
07/20/2026
Title Date Published Describes IncidentAuthorVisible
Hunting North Korea's job adverts on Google Docs2026-06-10TrueTrue
Parsing Google Docs HTML2026-04-24TrueTrue
Contagious Trader campaign - Coordinated weaponisation of cryptocurrency trading bots by suspected DPRK malware operators2026-03-17TrueTrue
First instance of PylangGhost RAT observed on npm2026-03-13TrueTrue
Novel DPRK stager using Pastebin and text steganography2026-02-26TrueTrue
Tracking DPRK operator IPs over time2026-02-22TrueTrue
DPRK tests Google Drive as a malware stager2026-02-21TrueTrue
Exposed DPRK reference malware and logs2026-02-16TrueTrue
VMWare artifacts left by a FAMOUS CHOLLIMA operator2026-02-13TrueTrue
Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign2023-03-05TrueTrue
Passive Takeover - uncovering (and emulating) an expensive subdomain takeover campaign2023-03-05TrueTrue
Fingerprinting C2s with Shodan2023-01-06TrueTrue
Tracking Crimson Kingsnake2023-01-06TrueTrue
Tracking Crimson Kingsnake2023-01-06TrueTrue
Fingerprinting C2s with Shodan2023-01-06TrueTrue

1–15 of 15