DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

2025-09-25 ESET

https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-from-primitive-crypto-theft-to-sophisticated-ai-based-deception/

Attachments

DeceptiveDevelopment.pdf (3 MB)

Thumbnail for DeceptiveDevelopment: From primitive crypto theft to sophisticated AI-based deception

ESET describes DeceptiveDevelopment as a North Korea-aligned financially motivated group active since at least 2023 and tightly connected to WageMole, the activity cluster associated with North Korean IT workers. Operators pose as recruiters on platforms such as LinkedIn, Upwork, Freelancer, and Crypto Jobs List, then use fake job interviews, coding challenges, private repositories, and ClickFix lures to compromise software developers, especially in cryptocurrency and Web3. The malware set is multiplatform and includes obfuscated Python and JavaScript scripts, BeaverTail and OtterCookie first-stage stealers, InvisibleFerret modular RAT components, WeaselStore infostealer/RAT code delivered with Go build tooling, and the newer TsunamiKit toolkit. The excerpt says DeceptiveDevelopment steals browser, wallet, keychain, and login data and can deploy remote-access tooling such as AnyDesk, while WageMole actors use compromised information, stolen identities, proxy interviewing, and AI-assisted synthetic identities to obtain real jobs. The campaign matters because it links malware-driven developer compromise with broader DPRK revenue-generation operations targeting the software and crypto hiring ecosystem.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 199.188.200.147 2025-09-25 2026-01-14
IPv4 103.231.75.101 2025-08-28 2026-01-14
IPv4 45.159.248.110 2025-08-28 2026-01-14
IPv4 164.132.209.191 2025-09-25 2025-09-25
IPv4 176.223.112.74 2025-09-25 2025-09-25
IPv4 116.125.126.38 2025-09-25 2025-09-25
IPv4 45.8.146.93 2025-04-02 2025-09-25
IPv4 86.104.72.247 2025-04-02 2025-09-25
IPv4 103.35.190.170 2025-04-02 2025-09-25

Related Actors

Related Reports

2025-02-20 • 42% Match
#BeaverTail #InvisibleFerret #DeceptiveDevelopment #T1027.013 #T1082 #T1119 #T1059.003 #T1140 #T1005 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1115 #T1083 #T1056.001 #T1059.006 #T1059.007 #T1204.002 #T1566.003 #T1555.003 #T1124 #T1583.003 #T1552.001 #T1585.001 #T1219 #T1133 #T1571 #T1564.001 #T1016 #T1074.001 #T1657 #T1071.002 #T1021.001 #T1614 #T1555.001 #T1217 #T1095 #T1025 #T1010 #T1560.002 #T1030 #T1567.004 #T1564.003
Shares tags: BeaverTail, InvisibleFerret, DeceptiveDevelopment • Same author: ESET
2025-08-13 • 30% Match
#Lazarus #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1584.004 #T1005 #T1070.004 #T1587.001 #T1041 #T1560 #T1608.001 #T1071.001 #T1046 #T1083 #T1056.001 #T1204.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1566.003 #T1124 #T1057 #T1059.005 #T1583.006 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1583.001 #T1059.001 #T1036.005 #T1132.001 #T1001.003 #T1585.001 #T1497.001 #T1105 #T1553.002 #T1620 #T1574.002 #T1562.001 #T1027.002 #T1489 #T1078 #T1008 #T1571 #T1491.001 #T1218 #T1220 #T1203 #T1189 #T1049 #T1564.001 #T1098 #T1016 #T1074.001 #T1588.002 #T1562.004 #T1591 #T1218.011 #T1583.004 #T1036.004 #T1588.003 #T1218.010 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1048.003 #T1134.002 #T1027.007 #T1021.001 #T1106 #T1090.001 #T1573 #T1070 #T1047 #T1574.013 #T1561.001 #T1036.003 #T1529 #T1055.001 #T1614.001 #T1010 #T1021.002 #T1033 #T1543.003 #T1485 #T1090.002 #T1542.003 #T1560.002 #T1012 #T1110 #T1547.009 #T1110.003 #T1534 #T1588.004 #T1104 #T1591.004 #T1561.002 #T1608.002 #T1202 #T1221 #T1557.001 #T1087.002 #T1560.003 #T1070.003 #T1021.004
Shares tags: T1071.001, T1056.001, T1204.001
« Back