logo

With AI’s help, North Korean hackers stumbled into a near-undetectable attack

ID: ec7cc429-5668-5180-9741-b3f8de1becb3

STIX ID: report--ec7cc429-5668-5180-9741-b3f8de1becb3

Feed Name: Help Net Security

Threat Score
90/100

Date Published: 2026-04-23

Date Updated: 2026-04-28

Author: Zeljka Zorz

...
...

Expel research attributes a North Korean APT subgroup dubbed HexagonalRodent that targets individual Web3 developers by posing as legitimate remote IT employers and delivering NodeJS/Python malware through malicious coding assessments and fake company websites; the group leverages AI tools (Cursor, ChatGPT, Anima) to develop and operationalize attacks, uses JavaScript obfuscation and 'vibe-coded' payloads to evade detection, and telemetry links the campaigns to the exfiltration of 26,584 cryptocurrency wallets (approximately $12M in assets potentially affected).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.