From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West

2024-11-04 Zscaler

https://www.zscaler.com/blogs/security-research/pyongyang-your-payroll-rise-north-korean-remote-workers-west

Thumbnail for From Pyongyang to Your Payroll: The Rise of North Korean Remote Workers in the West

North Korean operators behind Contagious Interview and WageMole continued using fake developer hiring activity to steal data and support remote job fraud in Western countries. Zscaler observed updated BeaverTail JavaScript and InvisibleFerret Python payloads with stronger obfuscation, dynamic code loading, Windows and macOS delivery formats, and OS specific persistence. The campaign targets web, cryptocurrency, and AI developers through attacker controlled GitHub repositories, social media contact, and fake job tasks. ThreatLabz reported more than 100 infected devices and theft of source code, cryptocurrency wallet data, browser data, personal information, keylogs, and clipboard content.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN degencryptojobs.com 2024-11-04 2024-11-04

Related Actors

Related Reports

« Back