North Korea-Aligned Void Dokkaebi Evolves with Binary Obfuscation
ID: 26c3334b-4331-507f-9b5d-40935d06f2fe
STIX ID: report--26c3334b-4331-507f-9b5d-40935d06f2fe
Feed Name: securityonline.info
Threat Score
**Executive summary:** TrendAI observed a North Korea-aligned APT (Famous Chollima) shift from readable Python implants to Cython-compiled native binaries (Void Dokkaebi) and a BeaverTail delivery framework that targets software developers via fake recruiter interviews to deploy trojanized browser extensions and steal credentials, private keys, and crypto wallet seed phrases while using obfuscation and runtime argument-based C2 overrides to evade detection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
