惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
J
Java Code Geeks
小众软件
小众软件
D
Docker
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
V
V2EX
博客园 - 叶小钗
GbyAI
GbyAI
Microsoft Azure Blog
Microsoft Azure Blog
Stack Overflow Blog
Stack Overflow Blog
B
Blog RSS Feed
酷 壳 – CoolShell
酷 壳 – CoolShell
博客园 - 【当耐特】
IT之家
IT之家
博客园 - 司徒正美
M
MIT News - Artificial intelligence
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
罗磊的独立博客
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog

Proofpoint News Feed

Proofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI Activity | Proofpoint US Four groups caught using the same Chrome and Windows exploit kit CISOs are feeling the security burden of accelerated AI use Chinese espionage groups swarm to exploit triple-link chain of zero-days Proofpoint 2026 Voice of the CISO Report Finds Cyber Resilience Improving, While AI Expands the CISO Mandate | Proofpoint US Proofpoint SOC Analyst Agent Uses OpenAI Cyber Models Proofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People Officer | Proofpoint US Proofpoint Brings OpenAI GPT Cyber Models into Security Operations to Help Defenders Investigate Threats Faster | Proofpoint US Cybercriminals Turn to Indirect Prompt Injection Attacks Fox News Proofpoint Joins Google Unified Security Recommended Program to Help Organizations Defend Against Today’s Most Sophisticated Threats | Proofpoint US Proofpoint Launches OEM Program to Help Security Providers Embed Trusted Threat Intelligence and Detection Capabilities | Proofpoint US Max-severity Exchange server flaw under active exploitation by Kremlin hackers New warnings that Russian operatives are targeting the emails of US nuclear scientists and defense contractors | CNN Politics International alert spotlights Russia-linked attacks on Zimbra webmail US and allies say Russian hackers stole emails without social engineering If you pay a hacker's ransom, chances are that they'll come back for more | TechCrunch Proofpoint Research Finds 65% of Organizations Affected by Ransomware Say AI Made Attacks More Effective | Proofpoint US The Hacker News Hackers find a new trick to collect Microsoft Entra user data without raising red flags Suspected Chinese snoops caught breaking into universities New Cargo Theft Surge: From Lobster Heists To Bourbon Warehouse Scams Defending the Authentication Flow: Device Code Phishing with Selena Larson Proofpoint Joins the OpenAI Daybreak Cyber Partner Program to Advance Responsible AI-Powered Cyber Defense | Proofpoint US OpenAI Lets Cyber Vendors Embed GPT-5.5 in Defenses China-Linked TA4922 Expands Phishing Attacks to U.K., Germany, Italy, and South Africa Proofpoint Introduces Active Exploits Protection to Help Organizations Prioritize Vulnerability Patching for Real-World Attacks in the AI Era | Proofpoint US Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks Proofpoint Integrates with the Claude Compliance API to Extend Data Security and Governance to Claude | Proofpoint US Proofpoint Launches Dedicated MSP Business Unit and Introduces 365 Total Protection for North America | Proofpoint US
Suspected North Korean actors use fake ‘coding assignment...
Laura French · 2026-06-09 · via Proofpoint News Feed

Phishing

Suspected North Korean threat actors are targeting developers with fake job offers and “coding assignments” that lead to the deployment of cross-platform malware for cryptocurrency and credential theft, Proofpoint reported Monday.

The threat cluster, tracked as UNK_DeadDrop, shows similarities to Contagious Interview and sent more than 250 emails across nearly 100 target companies over a six-week period between April and May 2026. The emails mostly targeted technology, education, business services, financial services, entertainment/media companies and telecommunications companies in the United States, with a particular focus on the cryptocurrency industry.

In the emails, the attackers pose as recruiters from legitimate companies such as the decentralized finance company Ondo Finance, the telehealth company Nourish and the Web3 and AI talent agency Hypen Connect, offering the target to apply for a software development role and complete a coding assignment.

In some cases, the attackers also presented as fake cryptocurrency and AI startups, with names like Pulsynk and Trixauvex, requesting the target for a peer-review of their code. In either case, the attacker included a link to a GitHub or GitLab repository with instructions to clone the repo to Visual Studio Code (VS Code) or Cursor code editors.

The repositories include a hidden tasks.json file that abuses VS Code and Cursor’s task automation abilities to automatically execute malicious files when a certain project folder is open in the editor. VS Code will prompt the user to approve the task execution while Cursor does not display a prompt, Proofpoint noted.

Related reading:

The malware acts differently depending on whether the victim is using Windows, Linux or macOS.

On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attacker’s servers.

On Windows systems, the attack chain runs as JavaScript within the code editor’s Electron process and performs a single infostealer operation without persistence, Proofpoint said.

The Overlord RAT first extracts browser wallet extensions and standalone wallet directories and transmits them as a ZIP archive to the C2 server. Five minutes later, it displays a fake system dialog prompt for the user to enter their system password, leveraging a Mach-O binary on macOS systems and the Zenity tool on Linux systems. If the user enters their password, the malware leverages the password to extract browser credentials from Keychain and GNOME Keyring and subsequently relaunches itself as root to perform further Keychain and GNOME Keyring dumps.

On Windows, the malicious task launches a VBScript that calls a CMD file, which then decodes an additional embedded script that stages three encrypted payloads. These payloads are decrypted at runtime and serve to facilitate infostealing capabilities.

The malware scans for 35 Chromium browser wallet extensions and 18 standalone wallet applications and also uses a Python-based stealer to extract passwords from Chromium and Firefox browsers, and cookies from Chrome, Edge and Brave browsers. The stolen data is sent to the C2 server via an HTTP POST request.

The malicious task also installs a malicious VSIX extension that enables persistence on Linux and macOS machines, causing the malware processes to be relaunched every time VS Code or Cursor are opened. This extension is installed on Windows machines but does not re-execute the malicious operation on these machines.

Proofpoint found that UNK_DeadDrop mainly emailed victims from domains registered via Namecheap set up with MailHostBox mailservers. Some of the domains were hosted on Vercel and included websites promoting the fake startups that were likely AI-generated, the researchers said.

UNK_DeadDrop’s victim targeting, social-engineering techniques and theft of cryptocurrency wallets and credentials overlap with the North Korean Contagious Interview campaign. However, this cluster shows some distinct techniques such as the use of email rather than social media channels like  LinkedIn to contact victims, the abuse of task.json auto-execution rather than npm installation, and the use of Overlord Go binaries rather than other malware known to be used by Contagious Interview, such as OtterCookie and FlexibleFerret.

“The consistent creation of new GitHub repositories as well as a new malware framework with iterative builds and a stealthy new execution and persistence technique through VSIX extensions demonstrates dedicated resourcing and active development of tooling,” the researchers concluded.

Laura French

Related

Shopify was considered one of the more innovative companies in 2020 for the way it emerged at a go-to ecommerce brand during the pandemic. Today’s columnist, Alex Moiseev of Kaspersky, says companies need to focus on innovation to survive and thrive in the year ahead. (Credit: CC 0 1.0)

AI hacker holding a glowing red chip symbolizing artificial intelligence in cybercrime, darkweb, and digital technology threat for cybersecurity and malware protection.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news