How to Get Scammed (by DPRK Hackers)
2026-01-14 • OZ •
https://medium.com/@0xOZ/how-to-get-scammed-by-dprk-hackers-b2f7588aea76
The write-up documents a developer recruitment scam presented as DPRK-linked activity under DEV#POPPER, Contagious Interview, and the XCTDH technique. A Discord persona posing as a hiring lead for a React developer role approached targets in developer and crypto communities, used a plausible company and job-posting story, and directed the victim to a GitHub React technical assessment repository. The obvious package metadata and server entry point appeared clean, but dynamic analysis showed the project contacting express-project-ifm6fa.fly.dev after startup. The malicious trigger was hidden in config/database.js, which fetched JSON, extracted obfuscated JavaScript from a description field, and evaluated it as a payload, illustrating how fake interview tasks can hide execution paths outside the files developers usually inspect first.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | api.trongrid.io | 2025-10-27 | 2026-05-31 |
| DOMAIN | fullnode.mainnet.aptoslabs.com | 2025-10-27 | 2026-05-31 |
| IPv4 | 23.27.120.142 | 2025-10-20 | 2026-04-21 |
| URL | https://api.trongrid.io/v1/acco… | 2026-01-14 | 2026-04-11 |
| URL | https://fullnode.mainnet.aptosl… | 2026-01-14 | 2026-04-11 |
| DOMAIN | bsc-dataseed.binance.org | 2025-10-27 | 2026-04-11 |
| DOMAIN | bsc-rpc.publicnode.com | 2025-10-27 | 2026-04-11 |
| HASH | 64cc940af0ebea2626d156bdac505c3c | 2026-01-14 | 2026-01-14 |
| HASH | 46cc7e5c6c4a9c9dcc1cf95b30d780a8 | 2026-01-14 | 2026-01-14 |
| HASH | 9f8033bf9e669aa8043f46733f73dd9… | 2026-01-14 | 2026-01-14 |
| HASH | b1032815b078aad59eb3bd32c29dee4… | 2026-01-14 | 2026-01-14 |
| URL | https://forum.plutonium.pw/user… | 2026-01-14 | 2026-01-14 |
| URL | https://fullnode.mainnet.aptosl… | 2026-01-14 | 2026-01-14 |
| URL | https://www.ransom-isac.com/blo… | 2026-01-14 | 2026-01-14 |
| URL | https://app.malva.re/file/64cc9… | 2026-01-14 | 2026-01-14 |
| URL | https://api.trongrid.io/v1/acco… | 2026-01-14 | 2026-01-14 |
| URL | https://bsc-rpc.publicnode.com | 2026-01-14 | 2026-01-14 |
| URL | https://www.answeroverflow.com/… | 2026-01-14 | 2026-01-14 |
| DOMAIN | app.malva.re | 2026-01-14 | 2026-01-14 |
| DOMAIN | express-project-ifm6fa.fly.dev | 2026-01-14 | 2026-01-14 |
| DOMAIN | forum.plutonium.pw | 2026-01-14 | 2026-01-14 |
| IPv4 | 108.165.100.36 | 2026-01-14 | 2026-01-14 |
| IPv4 | 23.27.13.242 | 2026-01-14 | 2026-01-14 |
| URL | https://bsc-dataseed.binance.org | 2025-10-27 | 2026-01-14 |