Velvet Chollima Leaves Backend Keys Inside Critical GitLab Dead-Drop Malware
ID: 4e0bee9f-5778-513f-b397-1709f6fafa85
STIX ID: report--4e0bee9f-5778-513f-b397-1709f6fafa85
Feed Name: securityonline.info
Researchers uncovered a financially motivated, North Korean-linked espionage campaign using a signed Windows MSI (masquerading as “Tralert FX”) that installs a multi-stage infostealer and keylogger. The actors abused an EV code-sign certificate to evade detection and exfiltrated keystrokes, session cookies, and trading credentials by committing data to private GitLab repositories on a 30-minute cycle; investigators found over 4,100 commits and around 90 compromised hosts, and observed hardcoded credentials and GitLab tokens in the distributed payload.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
