
2/19/2026 · Oliver Smith
What this post added
This post details North Korean threat actors' tradecraft, including the use of JavaScript-based malware (BeaverTail, Ottercookie), custom obfuscation techniques, abuse of legitimate services for payload hosting (e.g., Vercel), and the use of VS Code tasks for malware execution. It also highlights the parallel operation of distinct threat actor teams and the technical proficiency variations observed.