Google's Threat Analysis Group has reported an active North Korean campaign targeting security researchers, using social media and encrypted messaging apps to build rapport and send malicious files. The campaign has been ongoing for over two years, with at least one actively exploited 0-day vulnerability being used to target researchers. The threat actors have also developed a standalone Windows tool that can download and execute arbitrary code from an attacker-controlled domain. The vulnerability has been reported to the affected vendor and a patch has been issued.