
A North Korea-aligned exercise cluster tracked by ESET as DeceptiveDevelopment drains victims’ crypto wallets and steals their login particulars from net browsers and password managers
20 Feb 2025
ESET researchers have noticed a malicious marketing campaign the place North Korea-aligned risk actors, posing as headhunters, goal freelance software program builders with info-stealing malware.
The actions – named DeceptiveDevelopment and going again to not less than November 2023 – contain spearphishing messages which can be being distributed on job-hunting and freelancing websites and ask the targets to take a coding take a look at, with the recordsdata mandatory for the duty often hosted on non-public repositories reminiscent of GitHub. These recordsdata are laden with malware, nevertheless, which finally lets the attackers steal the victims’ login particulars and drain their cryptocurrency wallets.
What else is there to know concerning the marketing campaign’s techniques, methods, and procedures? Be taught from ESET Chief Safety Evangelist Tony Anscombe within the video and ensure to learn the full blogpost.