New “StoatWaffle” Malware Emerges in North Korean “Contagious Interview” Campaign
ID: 20899f75-f236-5d52-a4d4-bbf9726f13c8
STIX ID: report--20899f75-f236-5d52-a4d4-bbf9726f13c8
Feed Name: securityonline.info
NTT Security Japan researchers discovered StoatWaffle, a Node.js-based modular malware used by North Korean-linked WaterPlum Team 8. The campaign uses malicious Git/VSCode repositories that auto-trigger a tasks.json task on folder open to download a bootstrap, install Node.js if needed, and deploy a downloader (env.npl) that launches modules for credential theft (browsers, extensions, macOS Keychain) and a RAT that persists and polls C2; the malware also converts Windows paths for access via WSL.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
