- Module 01 The organisation How the units are structured, who does what, and why it matters which one is at your door.
- Module 02 Social engineering and intrusion Fake recruiters, poisoned coding tests, long-game personas, compromised developer machines and signing infrastructure.
- Module 03 IT workers in your hiring pipeline How North Korean remote workers get hired, what they do once inside, and what to look for.
- Module 04 Laundering and cash-out How stolen funds move after a hack, from the first swap to the last OTC desk.
Threat briefings
Know your adversary. Intelligence is armour.
Briefings for boards, security teams and financial-crime teams on the actors targeting crypto: who they are, how they operate, who they choose, what it looks like when they come for you, and where the money goes afterwards.
The first step to building your defences is understanding the threats you face.
Threat briefings
Three briefings, each in modules you can take together or separately
The Com
A loose, largely English-speaking network of young cybercriminals. Less sophisticated than DPRK, far more prolific, and unusually good at getting people to do things.
Book this briefing- Module 01 How the network works Who's in it, how it organises, and how access, data and victims are traded.
- Module 02 Support impersonation and help-desk attacks Fake support, fake staff, and the SIM swaps and resets that follow.
- Module 03 Social account takeovers How X, Instagram and Discord accounts are taken, and how they're turned into money.
- Module 04 Drainers and phishing Drainer-as-a-service kits, malicious approvals and signatures, address poisoning, and fake sites pushed through ads and social media.
- Module 05 Breaches and extortion Data breaches, insider recruitment, doxxing and the extortion that follows.
Romance baiting
Industrialised investment fraud run from scam compounds. The largest fraud typology in crypto by volume, and the one most likely to be moving through your platform right now. This is commonly known as “pig butchering”.
Book this briefing- Module 01 The compounds Who runs them, who works in them, and how a campaign is organised.
- Module 02 The grooming playbook How victims are found, groomed and coached, from first contact to the last deposit.
- Module 03 What it looks like on-chain Victim deposits, consolidation wallets, and the cash-out routes through exchanges and OTC.
- Module 04 Signals a platform can act on What to look for in your own flows, what to escalate, and how to warn customers before the money leaves.
Attack vectors
By method rather than by actor; add to any briefing
Exploits
How smart-contract and protocol vulnerabilities are found, weaponised and cashed out, and what the first minutes after an exploit look like.
Supply chain compromise
Compromised dependencies, build pipelines and developer tooling: how an attacker gets into what you ship, and the signals that give it away.
Signing and key-management attacks
How attackers subvert multisig and transaction-signing processes, and what good signing hygiene looks like.
DNS and front-end hijacking
Registrar and DNS account takeovers that turn a trusted domain against its own users, and the controls that close the gap.
Governance attacks
How voting power is bought, borrowed or captured to push through a hostile proposal, and the controls that make it harder.
MEV and the dark forest
Front-running, sandwich attacks and the bots that watch the mempool: what happens to a transaction between broadcast and inclusion, and what that means for you.
AI-enabled threats
Deepfaked calls, cloned voices, synthetic personas and phishing at scale: what has actually changed, and what hasn't.
How the money moves
How each of these groups launders what they take, what's detectable at each stage, what's freezable and when, and what the first hour after a theft should look like.
Bespoke
Something else? We'll build a briefing around your sector, your systems and what you've seen.
Tell us what you needWho it's for
Boards & executives
What these actors want from a company like yours, in plain language, and the decisions that follow. Executive briefing, or a standing quarterly update.
Security & engineering teams
Tradecraft in detail: approaches, tooling and the signals that show up before and during an attack. DPRK and Com workshops.
Compliance & financial-crime teams
How stolen and defrauded funds move, what the typologies look like on your platform, and what to escalate. The romance-baiting briefing and the How the money moves module.
Whole organisation
Staff awareness built on how these actors actually approach people, not generic security training.
Formats
Four ways to run it
Executive briefing
60–90 minutesFor leadership and boards. Non-technical, focused on exposure and decisions.
Team workshop
Half a dayFor security, engineering or compliance teams. Tradecraft, warning signs, detection and response.
Standing briefing
QuarterlyA regular update for a board or security team on what's changed: new tradecraft, new campaigns, and what it means for you.
Ask about a standing briefingWritten threat brief
DocumentA tailored briefing document on the actors and tradecraft relevant to your organisation.
Remote, or in person. Pricing on request.
Delivered by
Pangolin Intelligence is led by tanuki42, a pseudonymous crypto security researcher and SEAL 911 contributor.
Know your adversary.
