DevPopper Campaign Targets Software Developers

2024-08-26 Poly Swarm

https://blog.polyswarm.io/devpopper-campaign-targets-software-developers

Thumbnail for DevPopper Campaign Targets Software Developers

PolySwarm summarizes DevPopper activity in which threat actors use fake job interviews to target software developers and deliver a Python-based RAT. The infection chain begins when developers are asked to download and run GitHub-hosted code, leading an NPM package to execute obfuscated JavaScript that uses Node.js and curl to retrieve a second-stage archive from C2. DevPopper collects system, host, and network data and supports remote access, file search and theft, command execution, clipboard logging, and keylogging. The excerpt says Securonix assessed the campaign as likely North Korean based on similar historical activity, while victims were observed in South Korea, North America, Europe, and the Middle East. Updated variants expand targeting across Linux, Windows, and macOS and add FTP, encrypted file upload, browser credential and cookie theft, stronger obfuscation, and directory traversal capabilities.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 63238b8d083553a8341bf6599d3d601… 2024-07-31 2024-08-26
HASH bc4a082e2b999d18ef2d7de1948b2bf… 2024-07-31 2024-08-26
HASH 2d10b48454537a8977affde99f6edcb… 2024-07-31 2024-08-26
HASH 33617f0ac01a0f7fa5f64bd8edef737… 2024-04-25 2024-08-26

Related Reports

« Back