Critical

76% of All Crypto Stolen in 2026 Is Now in North Korea

darkreading
Actively Exploited

Overview

North Korean hackers are increasingly targeting cryptocurrency, with reports indicating that 76% of all stolen crypto in 2026 has ties to the country. These attacks have become so frequent that they are occurring on a weekly basis, raising concerns among security experts. Researchers suggest that artificial intelligence may be playing a role in these sophisticated heists, potentially enhancing the attackers' capabilities. This trend poses significant risks not only to individual investors but also to the broader cryptocurrency market, which is already vulnerable to theft and fraud. As these incidents escalate, it becomes crucial for users and companies to strengthen their security measures to protect against such attacks.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Cryptocurrency platforms, wallets, exchanges
  • Action Required: Users and companies should enhance security protocols, including multi-factor authentication and regular security audits.
  • Timeline: Ongoing since 2026

Original Article Summary

North Korean threat actors are pulling off historic cryptocurrency heists on a yearly, sometimes weekly basis now. AI might be helping them.

Impact

Cryptocurrency platforms, wallets, exchanges

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Ongoing since 2026

Remediation

Users and companies should enhance security protocols, including multi-factor authentication and regular security audits.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

The Hacker News

In June 2026, a new malware framework named GoCaracal was identified during an intrusion at a communications organization in Venezuela. Linked to the Dark Caracal group, this Go-based malware allows attackers to gain remote shell access and execute malicious payloads. It also has capabilities for stealing browser data, logging keystrokes, and controlling remote desktops. The use of Ethereum smart contracts to dynamically fetch replacement command-and-control (C2) addresses makes it particularly sophisticated and harder to track. This incident is concerning as it highlights the evolving tactics of cybercriminals and the potential risks to sensitive information within the communications sector.

Aug 27, 2026

CISA orders feds to patch Citrix NetScaler RCE flaw by Saturday

BleepingComputer

The Cybersecurity and Infrastructure Security Agency (CISA) has mandated that U.S. government agencies must address a serious remote code execution vulnerability affecting Citrix NetScaler appliances by this Saturday. This flaw is currently being exploited by attackers, which raises urgent concerns for the security of government networks. Citrix NetScaler is widely used for application delivery and load balancing, making it critical for agencies to implement the patch to prevent unauthorized access and potential data breaches. The deadline emphasizes the need for swift action to mitigate risks, as failure to patch could lead to significant security incidents. Agencies are strongly advised to prioritize this update to protect their systems and sensitive information.

Aug 27, 2026

ATF confirms “major incident” after recent Qilin breach claims

BleepingComputer

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that one of its systems was compromised following claims from the Qilin ransomware group. This breach raises significant concerns as the ATF is responsible for enforcing federal laws related to firearms and explosives in the U.S. The agency has not disclosed specific details about what information may have been accessed or how the breach occurred. The incident is particularly troubling given the sensitive nature of the data the ATF handles. With ongoing threats from ransomware groups, this incident underscores the need for robust cybersecurity measures within federal agencies to protect critical information.

Aug 27, 2026

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The Hacker News

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, indicating that they are being actively exploited. Among these, a significant high-severity flaw affects Citrix NetScaler ADC and NetScaler Gateway, allowing for remote code execution. This vulnerability, identified as CVE-2019-1068, poses a serious risk to organizations using these products, as attackers can potentially gain full control of affected systems. Other vulnerabilities listed impact Linux and SQL Server products, underscoring a wide array of systems at risk. Organizations using these technologies should prioritize applying patches and implementing security measures to mitigate these threats.

Aug 27, 2026

Ring adopts new TAKE encryption standard for smart home devices

SCM feed for Latest

Ring has adopted a new encryption standard called TAKE for its smart home devices. This standard uses a rotating set of encryption keys that are temporarily stored in the cloud, allowing Ring to secure active user features. The implementation of TAKE is designed to enhance the security of user data and improve the overall safety of smart home devices. While this development aims to bolster encryption practices, it raises questions about the security of cloud-stored keys and how they are managed. Users of Ring devices should stay informed about these changes to understand how their data is protected and what potential vulnerabilities may exist in the cloud storage approach.

Aug 26, 2026

Nimbus Manticore expands infrastructure and malware arsenal

SCM feed for Latest

Nimbus Manticore, linked to the Tortoiseshell hacking group, has expanded its capabilities by deploying a new SSH-based tunneling tool and a C++ backdoor that resembles its existing malware known as TWOSTROKE. This development indicates a shift in tactics, allowing attackers to establish more secure communications with compromised systems. The increase in their malware arsenal raises concerns for organizations that may be targeted, as it suggests a growing sophistication in their operations. Companies need to be vigilant and enhance their defenses against potential intrusions, especially those using SSH protocols. The implications of this escalation could lead to more successful breaches and data exfiltration if not addressed promptly.

Aug 26, 2026