Void Dokkaebi Hackers Use Fake Job Interviews to Spread Malware via Code Repositories
ID: fdbd322f-88ef-5967-b2ad-a6ba259fba2f
STIX ID: report--fdbd322f-88ef-5967-b2ad-a6ba259fba2f
Feed Name: cybersecurityNews.com
Trend Micro researchers attribute a campaign to North Korea-linked Void Dokkaebi that tricks developers into cloning and running malicious repositories during fake interviews; the attackers use autorunning VS Code workspace tasks and injected obfuscated JavaScript to deliver a DEVSPOPPER RAT, rewrite commit history via temp_auto_push.bat, and propagate worm-like across public repositories (750+ infected repos, 500+ malicious VS Code task configs, 101 commit-tampering instances). Recommended mitigations include running interview code in isolated disposable environments, adding .vscode to .gitignore, enforcing signed commits and PR protections, auditing repos for infection markers and temp_auto_push.bat, and monitoring developer workstation outbound connections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
