North Korean Phishing Campaign Targets Developers to Steal Cryptocurrency
ID: 4cdf76c7-be7d-5a15-a824-9b869996a2d8
STIX ID: report--4cdf76c7-be7d-5a15-a824-9b869996a2d8
Feed Name: ThreatCluster
A North Korea-aligned phishing campaign labeled UNK_DeadDrop sent over 250 job-offer-style emails to nearly 100 organizations in April–May 2026, luring developers to attacker-controlled Git repositories that trigger a hidden tasks.json to install a malicious VSIX and deploy cross-platform malware (Go and JavaScript payloads) to exfiltrate developer credentials, API tokens and cryptocurrency wallets; Proofpoint and other sources confirmed the activity and GitLab removed the repository after notification. Recommended actions include blocking attacker domains/repos, detecting malicious VSIX and unusual VS Code/Cursor task activity, restricting editor-triggered script execution, and enforcing MFA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
