AI-Assisted Lazarus Campaign Targets Developers With Backdoored Coding Challenges
ID: c534ea25-582a-5155-954a-9f5a483a75cb
STIX ID: report--c534ea25-582a-5155-954a-9f5a483a75cb
Feed Name: cybersecurityNews.com
A North Korean-linked APT subgroup called HexagonalRodent is running a large-scale campaign targeting Web3 developers by sending malicious take-home coding assessments and fake job offers; malware embedded in VSCode project files (tasks.json) and source code installs BeaverTail (credential stealer), OtterCookie and InvisibleFerret (remote access), enabling exfiltration of 26,584 crypto wallets from 2,726 systems (public keys holding up to $12M exposed) and including a supply-chain compromise of a VSCode extension distributing OtterCookie. The group leverages generative AI to build convincing recruitment fronts and malware, and defenders are urged to disable automatic VSCode task execution, audit received code, use hardware wallet tokens, and monitor suspicious NodeJS/Python outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
