Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency
2026-06-08 • Proofpoint •
Proofpoint observed UNK_DeadDrop, a very likely North Korea-aligned developer phishing cluster, sending more than 250 emails to targets at nearly 100 organizations in April and May 2026, especially across cryptocurrency, finance, technology, education, and business services. The actor used recruitment, code-review, Foundry testing, and AI payments lures to drive developers to malicious GitHub and GitLab repositories that abused VS Code and Cursor task automation and installed a malicious VSIX extension. Linux and macOS payloads used Overlord-derived Go RATs with persistent WebSocket C&C, while the Windows chain ran JavaScript and Python inside the editor's Electron process to steal cryptocurrency wallets, browser credentials, keychain or keyring data, and standalone wallet artifacts. Proofpoint notes overlap with Contagious Interview tradecraft but tracks UNK_DeadDrop as a distinct cluster due to separate telemetry, email-based initial access, self-contained payloads, and distinct infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | nemesis.work | 2026-06-08 | 2026-06-08 |
| HASH | 09f9788e9cbdd3c1afba9adf01608b40 | 2026-06-08 | 2026-06-08 |
| HASH | 673c62aa3715ab32a789aeb7400aabf1 | 2026-06-08 | 2026-06-08 |
| HASH | 4298f7dbed45b433bbffd327df58f62d | 2026-06-08 | 2026-06-08 |
| HASH | 4cc11e4593e1d9cc66d56c21a668412e | 2026-06-08 | 2026-06-08 |
| HASH | da11df27377603c69a264cd2d3e62b94 | 2026-06-08 | 2026-06-08 |
| HASH | cdf75e09646eb558606241d8d2530c27 | 2026-06-08 | 2026-06-08 |
| HASH | 0e41db3aaea1a5b6be0a4ae89a4b921b | 2026-06-08 | 2026-06-08 |
| HASH | 96e1760ecc7e03a2cafa5750dd5ef3fa | 2026-06-08 | 2026-06-08 |
| HASH | 098222fb51cb20fb785949001eef306e | 2026-06-08 | 2026-06-08 |
| HASH | 5e20e4e369109ebfd2a2fdea14f43b1d | 2026-06-08 | 2026-06-08 |
| HASH | c8181861d255bbfdbc7c3f9a44387985 | 2026-06-08 | 2026-06-08 |
| HASH | f0249ec1c7025c84d3298d51d169f36b | 2026-06-08 | 2026-06-08 |
| HASH | 34820759e0f4a6ddaf59a636dd31a74d | 2026-06-08 | 2026-06-08 |
| HASH | 70280fd83204611bb107e14cd5e307fc | 2026-06-08 | 2026-06-08 |
| HASH | 582581dfa177bb8ec8a34be35a2f5316 | 2026-06-08 | 2026-06-08 |
| HASH | f455994f54b3454df3ac73647f249c91 | 2026-06-08 | 2026-06-08 |
| URL | https://gitlab.com/predict-toge… | 2026-06-08 | 2026-06-08 |
| URL | https://gitlab.com/trixauvex-or… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/mireles343/f… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/sr-werney/fo… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/rkama411/x40… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/skyjum/x402-… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/mireles343/f… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/ziobiri/forg… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/sr-werney/fo… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/Stomp47/rekt… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/wayout4u/rek… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/PedrinPY/rek… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/Trixauvex-or… | 2026-06-08 | 2026-06-08 |
| URL | https://github.com/Pulsynk/puls… | 2026-06-08 | 2026-06-08 |
| IPv4 | 170.205.29.83 | 2026-06-08 | 2026-06-08 |
| DOMAIN | migadyn.info | 2026-06-08 | 2026-06-08 |
| DOMAIN | domatisc.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | alphanonega.org | 2026-06-08 | 2026-06-08 |
| DOMAIN | raxvatange.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | onoplainai.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | valorecuiting.online | 2026-06-08 | 2026-06-08 |
| DOMAIN | coslyintra.online | 2026-06-08 | 2026-06-08 |
| DOMAIN | doxxela.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | asteara.org | 2026-06-08 | 2026-06-08 |
| DOMAIN | hyperdevpipline.org | 2026-06-08 | 2026-06-08 |
| DOMAIN | nowurisch.fit | 2026-06-08 | 2026-06-08 |
| DOMAIN | predictcareertogether.space | 2026-06-08 | 2026-06-08 |
| DOMAIN | togetherhire.fun | 2026-06-08 | 2026-06-08 |
| DOMAIN | careerpredictto.space | 2026-06-08 | 2026-06-08 |
| DOMAIN | predicttogether.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | predicttogerecruit.store | 2026-06-08 | 2026-06-08 |
| DOMAIN | predicttogetherrecruit.store | 2026-06-08 | 2026-06-08 |
| DOMAIN | careerpulsynk.xyz | 2026-06-08 | 2026-06-08 |
| DOMAIN | teampulsynk.team | 2026-06-08 | 2026-06-08 |
| DOMAIN | cotrixauvex.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | careertrixauvex.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | contactpulsynk.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | notifypulsynk.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | connectptogether.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | contactpredicttogether.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | recruitptogether.xyz | 2026-06-08 | 2026-06-08 |
| DOMAIN | talentnexhr.ink | 2026-06-08 | 2026-06-08 |
| DOMAIN | optixauvex.us | 2026-06-08 | 2026-06-08 |
| DOMAIN | elsavora.us | 2026-06-08 | 2026-06-08 |
| DOMAIN | culyrax.us | 2026-06-08 | 2026-06-08 |
| DOMAIN | ceronetwork.org | 2026-06-08 | 2026-06-08 |
| DOMAIN | deep-ai-guard.store | 2026-06-08 | 2026-06-08 |
| DOMAIN | ceronet.work | 2026-06-08 | 2026-06-08 |
| IPv4 | 170.205.30.227 | 2026-06-08 | 2026-06-08 |
| DOMAIN | nemesistrade.work | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | ondofinance.tech | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | nxlog.tech | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | empowerpharmacy.space | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected].… | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected]… | 2026-06-08 | 2026-06-08 | |
| [email protected]… | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected]… | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | mailtrixauvex.ink | 2026-06-08 | 2026-06-08 |
| [email protected]… | 2026-06-08 | 2026-06-08 | |
| DOMAIN | recruitvex.us | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | mailpulsynk.xyz | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | trixauvex.org | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected]… | 2026-06-08 | 2026-06-08 | |
| DOMAIN | onoplanoai.ink | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | trixauvexnet.ink | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | predicttocareer.space | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | mailpredicttogether.ink | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| DOMAIN | contacttrixauvex.ink | 2026-06-08 | 2026-06-08 |
| [email protected] | 2026-06-08 | 2026-06-08 | |
| [email protected] | 2026-05-25 | 2026-05-25 | |
| [email protected] | 2026-05-25 | 2026-05-25 | |
| URL | https://gitlab.com/pulsynk-org/… | 2026-05-25 | 2026-05-25 |
| DOMAIN | pulsynk.org | 2026-05-25 | 2026-05-25 |
| IPv4 | 23.137.105.75 | 2026-05-25 | 2026-05-25 |