Fake job interviews target developers with new Python backdoor
ID: 7042e241-60fa-55a4-a7ff-57b8506df62e
STIX ID: report--7042e241-60fa-55a4-a7ff-57b8506df62e
Feed Name: Bleeping Computer
Dev Popper is a multi-stage social-engineering campaign targeting software developers with fake job interviews that prompt victims to download an NPM package which ultimately deploys an obfuscated Python RAT; the malware enables persistent remote access, filesystem search and exfiltration (including FTP), remote execution, and keystroke/clipboard logging. Researchers observed the delivery chain (malicious NPM package -> Node.js curl stage -> downloaded Python payload) and note tactics consistent with North Korean groups, although attribution remains inconclusive.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
