logo

Inside “HexagonalRodent”: The AI-Powered DPRK Syndicate Hauling Millions in Crypto

ID: fc899455-9963-5698-b890-b883deee61f0

STIX ID: report--fc899455-9963-5698-b890-b883deee61f0

Feed Name: securityonline.info

Threat Score
88/100

Date Published: 2026-04-27

Date Updated: 2026-05-05

Author: Ddos

...
...

HexagonalRodent, a state‑linked North Korean threat group, is conducting a large-scale crypto theft campaign by posing as recruiters to deliver backdoored take‑home coding tests (using malware families BeaverTail, OtterCookie, InvisibleFerret) and abusing VSCode tasks.json to execute payloads; researchers attribute ~26,500 compromised wallets and an estimated $12M in exfiltrated assets in Q1 2026, with at least $1.1M traced to a DPRK‑controlled Ethereum address.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.