UNK_DeadDrop Phishing Campaigns Target Developers
ID: 63d12977-56c0-5ac2-8e79-e27ed6d30499
STIX ID: report--63d12977-56c0-5ac2-8e79-e27ed6d30499
Feed Name: securityonline.info
Researchers observed a sophisticated phishing campaign dubbed UNK_DeadDrop targeting software developers across ~100 organizations by sending fake job offers and code review requests that direct victims to actor-controlled GitHub repositories. The repositories abuse IDE features (tasks.json in .vscode, Cursor IDE behavior) to execute scripts that install a malicious VSIX and deploy an Overlord-based RAT (macOS/Linux native Go binaries; Windows in-memory Node.js) that exfiltrates cryptocurrency wallets, browser data, and credentials while maintaining persistence and performing anti-forensic cleanup; reporting links the activity to a North Korea-aligned group.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
