A North Korea-aligned exercise cluster tracked by ESET as DeceptiveDevelopment drains victims’ crypto wallets and steals their login particulars from net browsers and password managers
20 Feb 2025
ESET researchers have noticed a malicious marketing campaign the place North Korea-aligned menace actors, posing as headhunters, goal freelance software program builders with info-stealing malware.
The actions – named DeceptiveDevelopment and going again to not less than November 2023 – contain spearphishing messages which can be being distributed on job-hunting and freelancing websites and ask the targets to take a coding take a look at, with the information crucial for the duty normally hosted on personal repositories reminiscent of GitHub. These information are laden with malware, nonetheless, which in the end lets the attackers steal the victims’ login particulars and drain their cryptocurrency wallets.
What else is there to know in regards to the marketing campaign’s techniques, methods, and procedures? Study from ESET Chief Safety Evangelist Tony Anscombe within the video and ensure to learn the complete blogpost.