Inside Lazarus: How North Korea uses AI to industrialize attacks on developers
ID: 569e54d8-437f-5301-9dfa-e9c94464d667
STIX ID: report--569e54d8-437f-5301-9dfa-e9c94464d667
Feed Name: Expel Blog
Expel identifies and profiles "HexagonalRodent", a DPRK-linked APT subgroup that targets Web3 developers by distributing backdoored coding assessments and abusing NodeJS/Python malware families (BeaverTail, OtterCookie, InvisibleFerret). The report details large-scale exfiltration (26,584 wallets from 2,726 developer systems, up to $12M in exposed wallet public-key value), a supply-chain compromise of a VSCode extension, active C2 infrastructure (e.g., 195.201.104.53), heavy use of generative AI in operations, and internal workforce-tracking tooling used to coordinate teams and campaigns, with recommended detection opportunities and IoCs provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
