How to Get Scammed (by DPRK Hackers)

2026-01-14 OZ

https://medium.com/@0xOZ/how-to-get-scammed-by-dprk-hackers-b2f7588aea76

Thumbnail for How to Get Scammed (by DPRK Hackers)

The write-up documents a developer recruitment scam presented as DPRK-linked activity under DEV#POPPER, Contagious Interview, and the XCTDH technique. A Discord persona posing as a hiring lead for a React developer role approached targets in developer and crypto communities, used a plausible company and job-posting story, and directed the victim to a GitHub React technical assessment repository. The obvious package metadata and server entry point appeared clean, but dynamic analysis showed the project contacting express-project-ifm6fa.fly.dev after startup. The malicious trigger was hidden in config/database.js, which fetched JSON, extracted obfuscated JavaScript from a description field, and evaluated it as a payload, illustrating how fake interview tasks can hide execution paths outside the files developers usually inspect first.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN api.trongrid.io 2025-10-27 2026-05-31
DOMAIN fullnode.mainnet.aptoslabs.com 2025-10-27 2026-05-31
IPv4 23.27.120.142 2025-10-20 2026-04-21
URL https://api.trongrid.io/v1/acco… 2026-01-14 2026-04-11
URL https://fullnode.mainnet.aptosl… 2026-01-14 2026-04-11
DOMAIN bsc-dataseed.binance.org 2025-10-27 2026-04-11
DOMAIN bsc-rpc.publicnode.com 2025-10-27 2026-04-11
HASH 64cc940af0ebea2626d156bdac505c3c 2026-01-14 2026-01-14
HASH 46cc7e5c6c4a9c9dcc1cf95b30d780a8 2026-01-14 2026-01-14
HASH 9f8033bf9e669aa8043f46733f73dd9… 2026-01-14 2026-01-14
HASH b1032815b078aad59eb3bd32c29dee4… 2026-01-14 2026-01-14
URL https://forum.plutonium.pw/user… 2026-01-14 2026-01-14
URL https://fullnode.mainnet.aptosl… 2026-01-14 2026-01-14
URL https://www.ransom-isac.com/blo… 2026-01-14 2026-01-14
URL https://app.malva.re/file/64cc9… 2026-01-14 2026-01-14
URL https://api.trongrid.io/v1/acco… 2026-01-14 2026-01-14
URL https://bsc-rpc.publicnode.com 2026-01-14 2026-01-14
URL https://www.answeroverflow.com/… 2026-01-14 2026-01-14
DOMAIN app.malva.re 2026-01-14 2026-01-14
DOMAIN express-project-ifm6fa.fly.dev 2026-01-14 2026-01-14
DOMAIN forum.plutonium.pw 2026-01-14 2026-01-14
IPv4 108.165.100.36 2026-01-14 2026-01-14
IPv4 23.27.13.242 2026-01-14 2026-01-14
URL https://bsc-dataseed.binance.org 2025-10-27 2026-01-14

Related Actors

Related Reports

« Back