DPRK-Linked Malware Targeting Job Seekers via Wellfound
ID: c7409d1e-ca06-5681-b3ab-a39d3e49b432
STIX ID: report--c7409d1e-ca06-5681-b3ab-a39d3e49b432
Feed Name: ThreatCluster
Threat Score
A DPRK-linked campaign used a fake job interview on Wellfound to deliver a sophisticated Rust-compiled infostealer that exfiltrates browser passwords and crypto wallet data via a malicious script and fake password dialog; the malware contacts a C2 at cloudproxy.link, employs a custom cipher for config values (571 decrypted strings), had low VirusTotal detection, and the incident was reported to the FBI.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
