With AI’s help, North Korean hackers stumbled into a near-undetectable attack
ID: ec7cc429-5668-5180-9741-b3f8de1becb3
STIX ID: report--ec7cc429-5668-5180-9741-b3f8de1becb3
Feed Name: Help Net Security
Expel research attributes a North Korean APT subgroup dubbed HexagonalRodent that targets individual Web3 developers by posing as legitimate remote IT employers and delivering NodeJS/Python malware through malicious coding assessments and fake company websites; the group leverages AI tools (Cursor, ChatGPT, Anima) to develop and operationalize attacks, uses JavaScript obfuscation and 'vibe-coded' payloads to evade detection, and telemetry links the campaigns to the exfiltration of 26,584 cryptocurrency wallets (approximately $12M in assets potentially affected).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
