The US has seized 17 website domains allegedly used by North Korean IT workers in a scheme to defraud businesses and fund DPRK’s government arms programmes. The latest action reputedly followed seizures in October 2022 and January 2023 of about $1.5m of revenue earned through this scheme, showing the dire need for due diligence when hiring remote IT workers. The fraudulent sites made to look like genuine US-based services, coupled with false identities, have helped these IT workers infiltrate various businesses and raise funds for DPRK.

New Magecart Skimmer Attack With Malicious JavaScript Injection to Skim Payment Data
The threat landscape for e-commerce websites has once again shifted with the emergence of a sophisticated Magecart-style attack campaign, characterized by the deployment of obfuscated