Inside “HexagonalRodent”: The AI-Powered DPRK Syndicate Hauling Millions in Crypto
ID: fc899455-9963-5698-b890-b883deee61f0
STIX ID: report--fc899455-9963-5698-b890-b883deee61f0
Feed Name: securityonline.info
Threat Score
HexagonalRodent, a state‑linked North Korean threat group, is conducting a large-scale crypto theft campaign by posing as recruiters to deliver backdoored take‑home coding tests (using malware families BeaverTail, OtterCookie, InvisibleFerret) and abusing VSCode tasks.json to execute payloads; researchers attribute ~26,500 compromised wallets and an estimated $12M in exfiltrated assets in Q1 2026, with at least $1.1M traced to a DPRK‑controlled Ethereum address.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
