216.73.217.22

Slow Pisces Targets Developers With Coding Challenges and Introduces New Customized Python Malware

· Published 14/04/2025 18:55 · Modified 14/04/2025 20:48

Export JSON

Essential information

Published
14/04/2025 18:55
Modified
14/04/2025 20:48
Tags
2025-04-14 cryptocurrency dpkr infostealer north korea python rn loader rn stealer slow pisces social engineering yaml deserialization
Related entities
41 observables, 1 intrusion sets (apt), 2 malware, 3 others

Description

, a North Korean state-sponsored threat group, is targeting developers through LinkedIn with malicious coding challenges. The group impersonates recruiters and sends malware disguised as project tasks, infecting systems with and . Their campaign uses GitHub repositories containing adapted open-source projects in and JavaScript. The malware employs and EJS rendering to execute arbitrary code from command-and-control servers. has reportedly stolen over $1 billion from the sector in 2023, using various methods including fake trading applications and supply chain compromises. The group's operational security is noteworthy, with payloads existing only in memory and deployed selectively.

External references