Fake job offers target coders with infostealers

Date:

Share post:

A North Korea-aligned activity cluster tracked by ESET as DeceptiveDevelopment drains victims’ crypto wallets and steals their login details from web browsers and password managers

ESET researchers have observed a malicious campaign where North Korea-aligned threat actors, posing as headhunters, target freelance software developers with info-stealing malware.

The activities – named DeceptiveDevelopment and going back to at least November 2023 – involve spearphishing messages that are being distributed on job-hunting and freelancing sites and ask the targets to take a coding test, with the files necessary for the task usually hosted on private repositories such as GitHub. These files are laden with malware, however, which ultimately lets the attackers steal the victims’ login details and drain their cryptocurrency wallets.

What else is there to know about the campaign’s tactics, techniques, and procedures? Learn from ESET Chief Security Evangelist Tony Anscombe in the video and make sure to read the full blogpost.

Connect with us on Facebook, X, LinkedIn and Instagram.



Source link

spot_img

Related articles

6 Zero-Days in March 2025 Patch Tuesday – Krebs on Security

Microsoft today issued more than 50 security updates for its various Windows operating systems, including fixes for a...

Z890 vs B860: Which Chipset Should You Choose? – Custom Gaming & Workstation PC Blog

As a long-time system builder, understanding the nuances between Intel’s Z890 and B860 chipsets is crucial for optimizing...

Jonas Event Technology Welcomes Sarah Cox as New Managing Director

Jonas Event Technology (JET), a leading provider of event registration services and technology, is proud to...

Drive Operational Excellence with Odoo ERP software Solutions

Unlocking Operational Excellence Businesses that leverage ERP solutions like Odoo ERP have seen significant improvements in their operational...