Learn more about the DEV#POPPER remote access trojan and how to protect your organization from this threat.

2026-03-05 e Sentire

https://www.esentire.com/blog/north-korean-apt-malware-analysis-dev-popper-rat-and-omnistealer-everyday-im-shufflin

Thumbnail for Learn more about the DEV#POPPER remote access trojan and how to protect your organization from this threat.

eSentire TRU observed DEV#POPPER on an Energy, Utilities, and Waste customer machine in February 2026 and attributes the activity with high confidence to a North Korean state-sponsored APT based on shared TTPs with related campaigns. The intrusion began when the victim cloned the weaponized ShoeVista GitHub repository, launched its frontend, and triggered obfuscated JavaScript hidden in frontend/tailwind.config.js. The staged chain contacted 23.27.20[.]143 with custom headers, decrypted follow-on code with the XOR key "ThZG+0jfXE6VAGOJ", and ultimately loaded DEV#POPPER RAT plus the Python-based OmniStealer. The malware targets macOS most often but also supports Windows and Linux, with objectives including cryptocurrency wallet theft and access to developer secrets such as source-code credentials, API keys, passwords, and cloud tokens.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 198.105.127.210 2026-03-05 2026-06-12
IPv4 23.27.20.143 2025-10-20 2026-04-21
DOMAIN bsc-dataseed.binance.org 2025-10-27 2026-04-11
DOMAIN bsc-rpc.publicnode.com 2025-10-27 2026-04-11
HASH 9a47bb48b7b8ca41fc138fd3372e8cc0 2026-03-05 2026-03-05

Related Reports

« Back