logo

North Korea-Aligned Void Dokkaebi Evolves with Binary Obfuscation

ID: 26c3334b-4331-507f-9b5d-40935d06f2fe

STIX ID: report--26c3334b-4331-507f-9b5d-40935d06f2fe

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-05-28

Date Updated: 2026-05-28

Author: Ddos

...
...

**Executive summary:** TrendAI observed a North Korea-aligned APT (Famous Chollima) shift from readable Python implants to Cython-compiled native binaries (Void Dokkaebi) and a BeaverTail delivery framework that targets software developers via fake recruiter interviews to deploy trojanized browser extensions and steal credentials, private keys, and crypto wallet seed phrases while using obfuscation and runtime argument-based C2 overrides to evade detection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.