logo

North Koreans Target Devs Worldwide With Spyware, Job Offers

ID: 0a110ad9-c549-55a8-b57b-c1cabb8f8539

STIX ID: report--0a110ad9-c549-55a8-b57b-c1cabb8f8539

Feed Name: Dark Reading

Threat Score
82/100

Date Published: 2024-07-31

Date Updated: 2026-04-21

Author: Tara Seals, Managing Editor, News, Dark Reading

...
...

DEV#POPPER, a campaign linked to North Korean threat actors, lures software developers with faux interview npm-style ZIP packages that execute obfuscated JavaScript to deploy a multi-platform infostealer (Windows, Linux, macOS). The malware chain fetches additional payloads including Python-based stealers that exfiltrate files, browser cookies, credit-card data, and keylogs, uses C2 infrastructure and host identifiers, and employs directory-traversal and filtering to appear legitimate; the campaign has expanded globally and presents substantial risk to targeted developers and their employers.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.