North Korean APT groups have shifted focus to Ukrainian government agencies, aligning with Russian interests amid increasing geopolitical tensions. Since February 2025, they’ve employed sophisticated credential harvesting and malware techniques, primarily orchestrated by the Konni group via phishing attacks. Their methods include deceptive emails and PowerShell scripts, enabling persistent access and intelligence-gathering on military capabilities.

Report Links Los Pollos and RichAds to Malware Traffic Operations
Infoblox Threat Intel’s research demonstrates a hidden connection among cybercrime groups and seemingly lawful AdTech firms, including discovered shared tactics and infrastructure. The research was