logo

DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

ID: 878e7a3a-e419-5d1c-bd22-b136b1cb2751

STIX ID: report--878e7a3a-e419-5d1c-bd22-b136b1cb2751

Feed Name: WeLiveSecurity (ESET Research)

Threat Score
86/100

Date Published: 2025-09-25

Date Updated: 2026-05-01

...
...

This ESET blogpost summarizes a white paper on DeceptiveDevelopment, a North Korea‑aligned threat actor that uses fake recruiter profiles and ClickFix social engineering to deliver cross‑platform infostealers and RATs (BeaverTail, InvisibleFerret, WeaselStore, TsunamiKit, Tropidoor, AkdoorTea). It details the group's tactics, malware execution chains, infrastructure and OSINT linking to North Korean IT worker (WageMole) fraud-for-hire campaigns, and provides extensive IoCs and a MITRE ATT&CK mapping for defenders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.