logo

North Korean Phishing Campaign Targets Developers to Steal Cryptocurrency

ID: 4cdf76c7-be7d-5a15-a824-9b869996a2d8

STIX ID: report--4cdf76c7-be7d-5a15-a824-9b869996a2d8

Feed Name: ThreatCluster

Threat Score
76/100

Date Published: 2026-06-08

Date Updated: 2026-06-09

...
...

A North Korea-aligned phishing campaign labeled UNK_DeadDrop sent over 250 job-offer-style emails to nearly 100 organizations in April–May 2026, luring developers to attacker-controlled Git repositories that trigger a hidden tasks.json to install a malicious VSIX and deploy cross-platform malware (Go and JavaScript payloads) to exfiltrate developer credentials, API tokens and cryptocurrency wallets; Proofpoint and other sources confirmed the activity and GitLab removed the repository after notification. Recommended actions include blocking attacker domains/repos, detecting malicious VSIX and unusual VS Code/Cursor task activity, restricting editor-triggered script execution, and enforcing MFA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.