Malware was set to be deployed between 2027 and 2028 by nine of the dozen NuGet packages uploaded by shanhai666 between 2023 and 2024, according to The Register.
Investigation led by South Korean authorities revealed that leading mobile carrier KT Corp. had hidden multiple malware infections and breaches that resulted in a recent cyberattack involving illegal micro base stations, according to the Yonhap News Agency.
The attack, uncovered in July 2025, featured a phishing campaign using password-protected archives to distribute a new backdoor called BackDoor.ShellNET.1.