216.73.217.22

Targeting of freelance developers

· Published 21/02/2025 05:58 · Modified 21/02/2025 15:29

Export JSON

Essential information

Published
21/02/2025 05:58
Modified
21/02/2025 15:29
Tags
2025-02-21 beavertail cryptocurrency freelancers infostealer invisibleferret job scams north korea spearphishing
Related entities
1 intrusion sets (apt), 20 techniques (mitre), 2 malware, 1 others

Description

-aligned cybercriminals are targeting freelance software developers through fake job offers and coding challenges containing malware. The campaign, dubbed DeceptiveDevelopment, uses two main malware families - and - to steal wallets and login credentials. Attackers pose as recruiters on platforms like LinkedIn and GitHub, providing trojanized projects as part of fake interview processes. The malware steals browser data, wallets, and system information, and can deploy remote access tools. Hundreds of victims globally have been observed across Windows, Linux and macOS systems. The operation shows increasing sophistication and is expected to continue evolving its tactics to target users.

External references