216.73.217.22

Novel DPRK stager using Pastebin and text steganography

· Published 02/03/2026 17:08 · Modified 02/03/2026 21:43

Export JSON

Essential information

Published
02/03/2026 17:08
Modified
02/03/2026 21:43
Tags
2026-03-02 dprk javascript multi-platform npm pastebin stager steganography vercel
Related entities
5 observables, 1 intrusion sets (apt), 15 techniques (mitre)

Description

A new malicious campaign involving seventeen packages has been identified, utilizing and text as a dead-drop resolver. The attackers employ a complex decoding mechanism to extract C2 URLs from seemingly benign text on . The malware targets multiple platforms, including Windows, macOS, and Linux, downloading and executing platform-specific payloads. The infection chain involves multiple fallback domains hosted on , demonstrating a sophisticated approach to maintain persistence. This novel technique, along with other recent developments, indicates an accelerated pace of testing and development by the threat actor, suggesting continued iterations in their infection methodologies.

External references