DeceptiveDevelopment targets freelance developers

2025-02-20 ESET

https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-targets-freelance-developers/

Thumbnail for DeceptiveDevelopment targets freelance developers

ESET tracks DeceptiveDevelopment as a North Korea-aligned cluster that targets freelance software developers, especially people working on cryptocurrency and DeFi projects. Operators pose as recruiters or headhunters on job and freelancing platforms, then provide coding-test projects from private repositories or similar hosting that conceal malicious code. Running the project deploys BeaverTail as first-stage malware and can lead to InvisibleFerret, giving the operators theft and remote-access capability across Windows, Linux, and macOS. ESET links the cluster to DPRK-aligned activity through shared recruiting tradecraft, GitHub connections to North Korean IT-worker personas, and malware focused on browser, password-manager, and cryptocurrency-wallet data.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 95.164.17.24 2024-07-15 2026-04-01
IPv4 147.124.214.129 2024-05-10 2026-02-03
IPv4 147.124.214.237 2024-05-10 2026-01-21
DOMAIN ip-api.com 2022-11-14 2026-01-21
URL http://ip-api.com/json 2024-07-31 2026-01-20
IPv4 23.106.253.194 2024-09-04 2025-11-13
IPv4 185.235.241.208 2024-08-13 2025-11-13
IPv4 67.203.7.171 2024-05-10 2025-11-13
IPv4 135.125.248.56 2025-02-20 2025-02-20
DOMAIN mirotalk.net 2024-07-15 2025-02-20
IPv4 45.61.131.218 2024-05-10 2025-02-20

Related Actors

Related Reports

2025-02-12 • 40% Match
#APT43 #T1102.002 #T1082 #T1059.003 #T1567.002 #T1140 #T1005 #T1070.004 #T1587.001 #T1041 #T1608.001 #T1071.001 #T1112 #T1083 #T1056.001 #T1059.006 #T1204.001 #T1059.007 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1057 #T1059.005 #T1583.006 #T1518.001 #T1566.001 #T1547.001 #T1585.002 #T1053.005 #T1598.003 #T1583.001 #T1059.001 #T1036.005 #T1552.001 #T1585.001 #T1105 #T1219 #T1055 #T1553.002 #T1562.001 #T1027.002 #T1133 #T1190 #T1098 #T1016 #T1074.001 #T1588.002 #T1055.012 #T1587 #T1078.003 #T1071.002 #T1562.004 #T1550.002 #T1111 #T1071.003 #T1591 #T1003.001 #T1218.011 #T1593.002 #T1586.002 #T1588.005 #T1583.004 #T1036.004 #T1589.003 #T1594 #T1218.010 #T1557 #T1593.001 #T1218.005 #T1589.002 #T1584.001 #T1070.006 #T1021.001 #T1560.001 #T1176 #T1136.001 #T1543.003 #T1012 #T1534 #T1560.003 #T1007 #T1564.003 #T1114.003 #T1114.002 #T1564.002 #T1040 #T1546.001 #T1505.003
Shares tags: T1082, T1059.003, T1140 • Published within a month
« Back