Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency

2026-06-08 Proofpoint

https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal

Thumbnail for Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency

Proofpoint observed UNK_DeadDrop, a very likely North Korea-aligned developer phishing cluster, sending more than 250 emails to targets at nearly 100 organizations in April and May 2026, especially across cryptocurrency, finance, technology, education, and business services. The actor used recruitment, code-review, Foundry testing, and AI payments lures to drive developers to malicious GitHub and GitLab repositories that abused VS Code and Cursor task automation and installed a malicious VSIX extension. Linux and macOS payloads used Overlord-derived Go RATs with persistent WebSocket C&C, while the Windows chain ran JavaScript and Python inside the editor's Electron process to steal cryptocurrency wallets, browser credentials, keychain or keyring data, and standalone wallet artifacts. Proofpoint notes overlap with Contagious Interview tradecraft but tracks UNK_DeadDrop as a distinct cluster due to separate telemetry, email-based initial access, self-contained payloads, and distinct infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN nemesis.work 2026-06-08 2026-06-08
HASH 09f9788e9cbdd3c1afba9adf01608b40 2026-06-08 2026-06-08
HASH 673c62aa3715ab32a789aeb7400aabf1 2026-06-08 2026-06-08
HASH 4298f7dbed45b433bbffd327df58f62d 2026-06-08 2026-06-08
HASH 4cc11e4593e1d9cc66d56c21a668412e 2026-06-08 2026-06-08
HASH da11df27377603c69a264cd2d3e62b94 2026-06-08 2026-06-08
HASH cdf75e09646eb558606241d8d2530c27 2026-06-08 2026-06-08
HASH 0e41db3aaea1a5b6be0a4ae89a4b921b 2026-06-08 2026-06-08
HASH 96e1760ecc7e03a2cafa5750dd5ef3fa 2026-06-08 2026-06-08
HASH 098222fb51cb20fb785949001eef306e 2026-06-08 2026-06-08
HASH 5e20e4e369109ebfd2a2fdea14f43b1d 2026-06-08 2026-06-08
HASH c8181861d255bbfdbc7c3f9a44387985 2026-06-08 2026-06-08
HASH f0249ec1c7025c84d3298d51d169f36b 2026-06-08 2026-06-08
HASH 34820759e0f4a6ddaf59a636dd31a74d 2026-06-08 2026-06-08
HASH 70280fd83204611bb107e14cd5e307fc 2026-06-08 2026-06-08
HASH 582581dfa177bb8ec8a34be35a2f5316 2026-06-08 2026-06-08
HASH f455994f54b3454df3ac73647f249c91 2026-06-08 2026-06-08
URL https://gitlab.com/predict-toge… 2026-06-08 2026-06-08
URL https://gitlab.com/trixauvex-or… 2026-06-08 2026-06-08
URL https://github.com/mireles343/f… 2026-06-08 2026-06-08
URL https://github.com/sr-werney/fo… 2026-06-08 2026-06-08
URL https://github.com/rkama411/x40… 2026-06-08 2026-06-08
URL https://github.com/skyjum/x402-… 2026-06-08 2026-06-08
URL https://github.com/mireles343/f… 2026-06-08 2026-06-08
URL https://github.com/ziobiri/forg… 2026-06-08 2026-06-08
URL https://github.com/sr-werney/fo… 2026-06-08 2026-06-08
URL https://github.com/Stomp47/rekt… 2026-06-08 2026-06-08
URL https://github.com/wayout4u/rek… 2026-06-08 2026-06-08
URL https://github.com/PedrinPY/rek… 2026-06-08 2026-06-08
URL https://github.com/Trixauvex-or… 2026-06-08 2026-06-08
URL https://github.com/Pulsynk/puls… 2026-06-08 2026-06-08
IPv4 170.205.29.83 2026-06-08 2026-06-08
DOMAIN migadyn.info 2026-06-08 2026-06-08
DOMAIN domatisc.ink 2026-06-08 2026-06-08
DOMAIN alphanonega.org 2026-06-08 2026-06-08
DOMAIN raxvatange.ink 2026-06-08 2026-06-08
DOMAIN onoplainai.ink 2026-06-08 2026-06-08
DOMAIN valorecuiting.online 2026-06-08 2026-06-08
DOMAIN coslyintra.online 2026-06-08 2026-06-08
DOMAIN doxxela.ink 2026-06-08 2026-06-08
DOMAIN asteara.org 2026-06-08 2026-06-08
DOMAIN hyperdevpipline.org 2026-06-08 2026-06-08
DOMAIN nowurisch.fit 2026-06-08 2026-06-08
DOMAIN predictcareertogether.space 2026-06-08 2026-06-08
DOMAIN togetherhire.fun 2026-06-08 2026-06-08
DOMAIN careerpredictto.space 2026-06-08 2026-06-08
DOMAIN predicttogether.ink 2026-06-08 2026-06-08
DOMAIN predicttogerecruit.store 2026-06-08 2026-06-08
DOMAIN predicttogetherrecruit.store 2026-06-08 2026-06-08
DOMAIN careerpulsynk.xyz 2026-06-08 2026-06-08
DOMAIN teampulsynk.team 2026-06-08 2026-06-08
DOMAIN cotrixauvex.ink 2026-06-08 2026-06-08
DOMAIN careertrixauvex.ink 2026-06-08 2026-06-08
DOMAIN contactpulsynk.ink 2026-06-08 2026-06-08
DOMAIN notifypulsynk.ink 2026-06-08 2026-06-08
DOMAIN connectptogether.ink 2026-06-08 2026-06-08
DOMAIN contactpredicttogether.ink 2026-06-08 2026-06-08
DOMAIN recruitptogether.xyz 2026-06-08 2026-06-08
DOMAIN talentnexhr.ink 2026-06-08 2026-06-08
DOMAIN optixauvex.us 2026-06-08 2026-06-08
DOMAIN elsavora.us 2026-06-08 2026-06-08
DOMAIN culyrax.us 2026-06-08 2026-06-08
DOMAIN ceronetwork.org 2026-06-08 2026-06-08
DOMAIN deep-ai-guard.store 2026-06-08 2026-06-08
DOMAIN ceronet.work 2026-06-08 2026-06-08
IPv4 170.205.30.227 2026-06-08 2026-06-08
DOMAIN nemesistrade.work 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN ondofinance.tech 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN nxlog.tech 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN empowerpharmacy.space 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected].… 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN mailtrixauvex.ink 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN recruitvex.us 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN mailpulsynk.xyz 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN trixauvex.org 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN onoplanoai.ink 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN trixauvexnet.ink 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN predicttocareer.space 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN mailpredicttogether.ink 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
DOMAIN contacttrixauvex.ink 2026-06-08 2026-06-08
EMAIL [email protected] 2026-06-08 2026-06-08
EMAIL [email protected] 2026-05-25 2026-05-25
EMAIL [email protected] 2026-05-25 2026-05-25
URL https://gitlab.com/pulsynk-org/… 2026-05-25 2026-05-25
DOMAIN pulsynk.org 2026-05-25 2026-05-25
IPv4 23.137.105.75 2026-05-25 2026-05-25

Related Actors

Related Reports

« Back