A North Korea-aligned exercise cluster tracked by ESET as DeceptiveDevelopment drains victims’ crypto wallets and steals their login particulars from net browsers and password managers
20 Feb 2025
ESET researchers have noticed a malicious marketing campaign the place North Korea-aligned risk actors, posing as headhunters, goal freelance software program builders with info-stealing malware.
The actions – named DeceptiveDevelopment and going again to no less than November 2023 – contain spearphishing messages which can be being distributed on job-hunting and freelancing websites and ask the targets to take a coding take a look at, with the information essential for the duty normally hosted on personal repositories comparable to GitHub. These information are laden with malware, nonetheless, which finally lets the attackers steal the victims’ login particulars and drain their cryptocurrency wallets.
What else is there to know concerning the marketing campaign’s techniques, methods, and procedures? Study from ESET Chief Safety Evangelist Tony Anscombe within the video and ensure to learn the full blogpost.