North Korean APT Unleashes DEV#POPPER RAT via GitHub to Drain Crypto Wallets
ID: 9d20c567-e667-50f5-a073-3d76aa2c3125
STIX ID: report--9d20c567-e667-50f5-a073-3d76aa2c3125
Feed Name: securityonline.info
eSentire’s TRU uncovered DEV#POPPER, a sophisticated North Korean APT-linked campaign that lures developers to a malicious GitHub repo ("ShoeVista") whose hidden script retrieves obfuscated payloads from blockchain transactions to deploy a cross-platform RAT and OmniStealer targeting crypto wallets, developer credentials, and cloud tokens; the malware uses anti-analysis and environment checks, persists by injecting into Node.js applications (e.g., VS Code, Discord), exfiltrates data to C2 or Telegram, and eSentire published DEV#STOPPER.js to assist deobfuscation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
