DevPopper Campaign Targets Software Developers
2024-08-26 • Poly Swarm •
https://blog.polyswarm.io/devpopper-campaign-targets-software-developers
PolySwarm summarizes DevPopper activity in which threat actors use fake job interviews to target software developers and deliver a Python-based RAT. The infection chain begins when developers are asked to download and run GitHub-hosted code, leading an NPM package to execute obfuscated JavaScript that uses Node.js and curl to retrieve a second-stage archive from C2. DevPopper collects system, host, and network data and supports remote access, file search and theft, command execution, clipboard logging, and keylogging. The excerpt says Securonix assessed the campaign as likely North Korean based on similar historical activity, while victims were observed in South Korea, North America, Europe, and the Middle East. Updated variants expand targeting across Linux, Windows, and macOS and add FTP, encrypted file upload, browser credential and cookie theft, stronger obfuscation, and directory traversal capabilities.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 63238b8d083553a8341bf6599d3d601… | 2024-07-31 | 2024-08-26 |
| HASH | bc4a082e2b999d18ef2d7de1948b2bf… | 2024-07-31 | 2024-08-26 |
| HASH | 2d10b48454537a8977affde99f6edcb… | 2024-07-31 | 2024-08-26 |
| HASH | 33617f0ac01a0f7fa5f64bd8edef737… | 2024-04-25 | 2024-08-26 |