logo

Inside Lazarus: How North Korea uses AI to industrialize attacks on developers

ID: 569e54d8-437f-5301-9dfa-e9c94464d667

STIX ID: report--569e54d8-437f-5301-9dfa-e9c94464d667

Feed Name: Expel Blog

Threat Score
88/100

Date Published: 2026-04-22

Date Updated: 2026-04-27

...
...

Expel identifies and profiles "HexagonalRodent", a DPRK-linked APT subgroup that targets Web3 developers by distributing backdoored coding assessments and abusing NodeJS/Python malware families (BeaverTail, OtterCookie, InvisibleFerret). The report details large-scale exfiltration (26,584 wallets from 2,726 developer systems, up to $12M in exposed wallet public-key value), a supply-chain compromise of a VSCode extension, active C2 infrastructure (e.g., 195.201.104.53), heavy use of generative AI in operations, and internal workforce-tracking tooling used to coordinate teams and campaigns, with recommended detection opportunities and IoCs provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.