#DeceptiveDevelopment
#ESETresearch analyzed a campaign by #DeceptiveDevelopment targeting developers with trojanized coding tests. Posing as recruiters, the operators approach their targets on job-hunting platforms, aiming to steal their cryptocurrency wallets and more.
www.welivesecurity.com/en/eset-rese...
🧵 1/6
DeceptiveDevelopment targets freelance developers
ESET researchers have observed a cluster of North Korea-aligned activities that they named DeceptiveDevelopment and where its operators pose as headhunters and serve their targets with software projec...
www.welivesecurity.com
February 20, 2025 at 8:33 PM
#ESETresearch has uncovered the North Korea-aligned threat actor, DeceptiveDevelopment, targeting freelance developers with trojanized coding challenges and fake job interviews.
www.welivesecurity.com/en/eset-rese... 1/6
www.welivesecurity.com
September 25, 2025 at 9:24 AM
#ESETresearch’s very own Peter Kálnai along with Matěj Havránek will present at #VB2025 @virusbtn.bsky.social: “DeceptiveDevelopment and 🇰🇵 North Korean IT workers: from primitive crypto theft to sophisticated AI-based deception.” Join them in Berlin, September 25 at 14:30 CEST. 1/3
August 21, 2025 at 9:33 AM
DeceptiveDevelopment is a 🇰🇵-aligned activity cluster. The attackers target software developers on 🪟 Windows, 🐧Linux, and 🍎 macOS, regardless of geographical location, in order to maximize profits. 2/6
February 20, 2025 at 8:37 PM
🚨 @esetresearch.bsky.social uncovered a North Korea-aligned campaign targeting freelance developers with trojanized coding tests. Disguised as recruiters, attackers spread infostealers to collect sensitive data, while also leaving in a backdoor for subsequent activities.

#ESET #ProgressProtected
DeceptiveDevelopment targets freelance developers
ESET researchers have observed a cluster of North Korea-aligned activities that they named DeceptiveDevelopment and where its operators pose as headhunters and serve their targets with software projec...
www.welivesecurity.com
February 21, 2025 at 1:02 PM
🚨 Sahte iş tekliflerinin ardında kripto hırsızlığı var!

ESET Research, Kuzey Kore bağlantılı **DeceptiveDevelopment** grubunun sosyal mühendislik yöntemleriyle geliştiricileri hedef alarak **kripto para birimlerini çaldığını** ortaya koydu.

📖 Haberin tamamı için: bihaber.tr/sahte-is-tek...
Sahte İş Teklifleriyle Kripto Para Tuzağı - Bihaber
ESET, DeceptiveDevelopment grubunun sahte iş teklifleriyle kripto hırsızlıklarını inceledi. Sahte İş Teklifleriyle Kripto Para Tuzağı!
bihaber.tr
October 29, 2025 at 10:23 PM
North Korea-aligned groups, e.g., DeceptiveDevelopment, expanded their financially motivated campaigns using fake job listings and social engineering. Russian APTs intensified attacks against Ukraine and the EU, exploiting zero-day vulns. web-assets.esetstatic.com/wls/en/paper... 2/2
web-assets.esetstatic.com
May 19, 2025 at 12:30 PM
North Korean hackers (DeceptiveDevelopment) use fake job postings on LinkedIn & Upwork to infect developers (Windows, Linux, macOS) with malware (BeaverTail & InvisibleFerret). Malware steals crypto & credentials, granting remote access via AnyDesk.#DeceptiveDevelopmentMalware
February 21, 2025 at 10:39 AM
Closely linked to North Korean IT worker fraud schemes, DeceptiveDevelopment lures victims into cybercrime with promises of easy money. Our research outlines its role in the ecosystem of North Korea-aligned groups and how to defend against it. More: www.virusbulletin.com/conference/v... 3/3
Virus Bulletin :: DeceptiveDevelopment and North Korean IT workers: from primitive crypto theft to sophisticated AI-based deception
VB2025 presentation: DeceptiveDevelopment and North Korean IT workers: from primitive crypto theft to sophisticated AI-based deception, Matej Havranek
www.virusbulletin.com
August 21, 2025 at 9:33 AM
ESET's Peter Kálnai & Matěj Havránek introduce a paper they presented at #VB2025, in which they detail the operations of the North Korea-aligned threat actor DeceptiveDevelopment and its connections to North Korean IT worker campaigns. www.welivesecurity.com/en/eset-rese...
September 29, 2025 at 8:51 AM
-APT reports on Equation Group, DPRK's Contagious Interview, DPRK's DeceptiveDevelopment, Pangu Team
-Stately Taurus linked to ancient malware
-Chinese APT tools found in ransomware attacks
-PAN warns of new firewall exploit chain
-Atlassian&Cisco security updates
-Infosec compensation report
February 21, 2025 at 9:12 AM
DeceptiveDevelopment (aka ContagiousInterview) is a North Korea-aligned threat actor targeting freelance developers and crypto professionals. It uses fake job offers, AI-generated investor videos, and the WeaselStore backdoor delivered via fake interview sites (ClickFix). 2/3
August 21, 2025 at 9:33 AM
You can find the IoCs in our GitHub repo:
github.com/eset/malware...
🧵6/6
malware-ioc/deceptivedevelopment at master · eset/malware-ioc
Indicators of Compromises (IOC) of our various investigations - eset/malware-ioc
github.com
February 20, 2025 at 8:42 PM
The campaign primarily uses two malware families – the first, 🦫 BeaverTail, acts as a simple login stealer, extracting browser databases containing saved logins, and is a downloader for the second stage, InvisibleFerret. 3/6
February 20, 2025 at 8:39 PM
DeceptiveDevelopmentはフリーランス開発者をターゲットにしている

サイバー犯罪者は、企業の採用担当者を装い、偽の求人情報で標的にアプローチすることが知られています。結局のところ、潜在的な被害者が就職の可能性に気を取られている時ほど、攻撃に最適なタイミングはあるでしょうか? 2024年初頭以来、ESETの研究者は、北朝鮮と連携した一連の悪意のある活動を観察してきました。これらの活動では、ヘッドハンターを装った攻撃者が、情報窃取マルウェアを隠蔽するソフトウェアプロジェクトを標的に提供しようとしています。私たちはこの活動クラスターを「欺瞞的開発」と呼んでいます。
DeceptiveDevelopment targets freelance developers
ESET researchers have observed a cluster of North Korea-aligned activities that they named DeceptiveDevelopment and where its operators pose as headhunters and serve their targets with software projec...
www.welivesecurity.com
July 19, 2025 at 8:26 PM
ESET Research’s has a deep dive into DeceptiveDevelopment, North Korean crypto theft via fake job offers

ESET Research has released new findings on DeceptiveDevelopment, also known as Contagious Interview – a threat group aligned with North Korea that has grown increasingly active in recent years.…
ESET Research’s has a deep dive into DeceptiveDevelopment, North Korean crypto theft via fake job offers
ESET Research has released new findings on DeceptiveDevelopment, also known as Contagious Interview – a threat group aligned with North Korea that has grown increasingly active in recent years. The group is primarily focused on cryptocurrency theft, targeting freelance developers across Windows, Linux, and macOS platforms. The newly published research paper traces the group's evolution from early malware families to more advanced toolsets.
itnerd.blog
September 29, 2025 at 6:45 PM
#WeaselStore is an #infostealer used by the #APT group #DeceptiveDevelopment, which targets developers on multiple systems in web & cryptocurrency. Protect yourself by deploying our public #YARArules: https://bit.ly/3x34FdW
GitHub - reversinglabs/reversinglabs-yara-rules: ReversingLabs YARA Rules
ReversingLabs YARA Rules. Contribute to reversinglabs/reversinglabs-yara-rules development by creating an account on GitHub.
github.com
November 4, 2025 at 6:40 PM
北朝鮮のハッカーがサプライチェーン攻撃でオープンソース開発者を標的に

PolinRiderと呼ばれるこのキャンペーンは、2025年12月から継続されており、侵害されたGitHubリポジトリにJavaScriptローダーを注入することで、DEV#POPPERリモートアクセス型トロイの木馬(RAT)とOmniStealer情報窃盗マルウェアを仕掛けている。

PolinRiderは、 DeceptiveDevelopment、Operation Dream Job、ClickFake Interviewキャンペーンでも見られる戦術を含む、より広範なContagious Interview...
North Korean Hackers Target Open Source Developers in Supply Chain Attacks
North Korean hackers are targeting open source software developers with a backdoor and an information stealer as part of a broad supply chain campaign dubbed PolinRider.
www.securityweek.com
August 1, 2026 at 11:54 PM
北朝鮮のハッカーがフリーランス開発者を求人詐欺で標的にしマルウェアを拡散

フリーランスのソフトウェア開発者は、就職面接をテーマにした餌を利用して、BeaverTail および InvisibleFerret として知られるクロスプラットフォームのマルウェア ファミリを配布する進行中のキャンペーンのターゲットになっています。

北朝鮮に関連するこの活動は「DeceptiveDevelopment」というコードネームで呼ばれており、Contagious Interview(別名CL-STA-0240)、DEV#POPPER、Famous Chollima、PurpleBravo、Tenac...
North Korean Hackers Target Freelance Developers in Job Scam to Deploy Malware
North Korean hackers use fake job interviews on Upwork and GitHub to infect crypto developers with BeaverTail and InvisibleFerret malware, stealing cr
thehackernews.com
July 19, 2025 at 8:26 PM
Beware of Fake Job Interview Challenges Attacking Developers To Deliver Malware
Beware of Fake Job Interview Challenges Attacking Developers To Deliver Malware
A North Korea-aligned cybercriminal campaign dubbed DeceptiveDevelopment has been targeting freelance software developers through fake job interviews since early 2024. Posing as recruiters on platforms like LinkedIn, Upwork, and cryptocurrency-focused job boards, attackers lure victims with promising job opportunities or lucrative freelance projects. The ultimate goal is to trick developers into executing trojanized codebases that deploy malware designed to steal cryptocurrency wallet data, browser credentials, and sensitive system information. Researchers identified two primary malware families in this campaign: BeaverTail, an infostealer and downloader, and InvisibleFerret, a modular backdoor enabling remote access and data exfiltration. These tools are remain hidden within software projects that victims are asked to review or modify as part of a fake hiring challenge. Notably, the attackers exploit GitHub’s interface by appending malicious code after long comments, pushing it off-screen in the default editor view. Malicious code appended after a long comment pushing it off-screen in GitHub’s code editor (top) and the page source of just line #1 (Source – ESET) ESET researchers noted that this obfuscation technique increases the likelihood of victims unknowingly executing the malware. Technical Delivery: Hidden Code and Obfuscation The attackers’ reliance on social engineering is complemented by sophisticated technical tactics. BeaverTail, delivered as JavaScript or Qt-based executables, begins by decrypting hardcoded Command-and-Control (C&C) server details. For example, the IP address 147.124.214.237:1244 is split into base64-encoded fragments and rearranged to evade detection :- javascript host="yNDEuMjA4MTg1LjIzNS4" // Decoded to 147.124.214.237 via string manipulation DeceptiveDevelopment compromise chain (Source – ESET) Once executed, BeaverTail searches for browser extensions like MetaMask, Coinbase Wallet, and Phantom to exfiltrate cryptocurrency keys stored in id.json (Solana) or browser databases. It also harvests login credentials from Firefox, Chrome, and system keychains. InvisibleFerret, the second-stage payload, uses XOR encryption and modular Python scripts to maintain persistence. One sample decrypts its payload using a hardcoded key ( G01d*8@( ) and establishes a reverse shell for remote command execution. Browser credential decryption logic in InvisibleFerret (Source – ESET) The malware’s browser module targets Chrome, Brave, and Edge profiles to extract encrypted credentials, leveraging OS-specific decryption methods—such as win32crypt on Windows or secretstorage on Linux—to decode sensitive data. The campaign’s infrastructure relies on servers hosted by providers like RouterHosting and Majestic Hosting Solutions . C&C communication occurs over non-standard ports (1244, 3000) to blend with legitimate traffic. Recent updates to InvisibleFerret include FTP-based data exfiltration and integration with Telegram’s API for real-time credential theft, signaling evolving operational sophistication. Developers are advised to verify recruiter identities, avoid executing unsolicited projects, and monitor for anomalous network activity on ports 1224–1245. Collect Threat Intelligence on the Latest Malware and Phishing Attacks with ANY.RUN TI Lookup ->  Try for free The post Beware of Fake Job Interview Challenges Attacking Developers To Deliver Malware appeared first on Cyber Security News .
cybersecuritynews.com
February 27, 2025 at 12:26 PM
北朝鲜黑客组织‘DeceptiveDevelopment’如何针对自由职业开发者进行信息窃取

https://qian.cx/posts/6CBC95B8-97CC-450D-A3F1-DEFA902DDA42
February 25, 2025 at 12:21 PM