logo

North Korean Hackers Adopt Infostealer Spreading Tactics in Latest Campaign

ID: cb7cda31-b35f-502e-b337-b041b5b9cda2

STIX ID: report--cb7cda31-b35f-502e-b337-b041b5b9cda2

Feed Name: infostealers.com

Threat Score
78/100

Date Published: 2024-12-28

Date Updated: 2026-04-28

Author: Alon Gal

...
...

This report describes a North Korean-associated campaign that impersonates recruiters on LinkedIn to lure victims into staged interviews and then instructs them to run troubleshooting terminal commands that download multi-platform malware; the malware steals cryptocurrency (approximately $64,000 observed), and the report includes domain/script IOCs and multiple on-chain wallet addresses along with mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.