logo

DPRK-Linked Malware Targeting Job Seekers via Wellfound

ID: c7409d1e-ca06-5681-b3ab-a39d3e49b432

STIX ID: report--c7409d1e-ca06-5681-b3ab-a39d3e49b432

Feed Name: ThreatCluster

Threat Score
85/100

Date Published: 2026-04-07

Date Updated: 2026-04-07

...
...

A DPRK-linked campaign used a fake job interview on Wellfound to deliver a sophisticated Rust-compiled infostealer that exfiltrates browser passwords and crypto wallet data via a malicious script and fake password dialog; the malware contacts a C2 at cloudproxy.link, employs a custom cipher for config values (571 decrypted strings), had low VirusTotal detection, and the incident was reported to the FBI.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.