DeceptiveDevelopment targets freelance developers
2025-02-20 • ESET •
https://www.welivesecurity.com/en/eset-research/deceptivedevelopment-targets-freelance-developers/
ESET tracks DeceptiveDevelopment as a North Korea-aligned cluster that targets freelance software developers, especially people working on cryptocurrency and DeFi projects. Operators pose as recruiters or headhunters on job and freelancing platforms, then provide coding-test projects from private repositories or similar hosting that conceal malicious code. Running the project deploys BeaverTail as first-stage malware and can lead to InvisibleFerret, giving the operators theft and remote-access capability across Windows, Linux, and macOS. ESET links the cluster to DPRK-aligned activity through shared recruiting tradecraft, GitHub connections to North Korean IT-worker personas, and malware focused on browser, password-manager, and cryptocurrency-wallet data.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 95.164.17.24 | 2024-07-15 | 2026-04-01 |
| IPv4 | 147.124.214.129 | 2024-05-10 | 2026-02-03 |
| IPv4 | 147.124.214.237 | 2024-05-10 | 2026-01-21 |
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| URL | http://ip-api.com/json | 2024-07-31 | 2026-01-20 |
| IPv4 | 23.106.253.194 | 2024-09-04 | 2025-11-13 |
| IPv4 | 185.235.241.208 | 2024-08-13 | 2025-11-13 |
| IPv4 | 67.203.7.171 | 2024-05-10 | 2025-11-13 |
| IPv4 | 135.125.248.56 | 2025-02-20 | 2025-02-20 |
| DOMAIN | mirotalk.net | 2024-07-15 | 2025-02-20 |
| IPv4 | 45.61.131.218 | 2024-05-10 | 2025-02-20 |