North Korean Hackers Use Fake Coding Tasks to Steal Cryptocurrency (infosecurity-magazine.com)
- North Korean cluster UNK_DeadDrop sent 250+ phishing emails with fake coding tasks.
- Malicious repos on GitHub/GitLab auto-execute via hidden tasks.json in code editors.
- Malware steals cryptocurrency wallets, passwords, and cookies from multiple platforms.
- Proofpoint tracks as independent campaign, similar to but separate from Contagious Interview.
"A likely North Korean threat actor tracked as UNK_DeadDrop targeted software developers with phishing emails containing fake coding assignments. The campaign, active in April-May 2026, sent over 250 emails to nearly 100 organizations, primarily US-based tech, education, and finance firms including cryptocurrency companies. The emails linked to malicious GitHub or GitLab repositories that automatically execute malware when opened in code editors like VS Code or Cursor. The malware steals cryptocurrency wallets, passwords, and cookies. The operation shares similarities with the known 'Contagious Interview' campaign but is tracked separately by Proofpoint."
no comments yet.