Research Update: Threat Actors Behind the DEV#POPPER Campaign Have Retooled and are Continuing to Target Software Developers via Social Engineering
2024-07-31 • Securonix •
Securonix reports that the North Korea-linked DEV#POPPER operators continued targeting software developers with fake interview lures and a ZIP package containing hidden malicious JavaScript. The updated samples added support for Windows, Linux, and macOS, with obfuscated code that decodes a C2 endpoint at 67.203.7[.]171:1244. The malware identifies the host platform, builds paths and variables for each operating system, collects system information, and sends the data to the remote server over HTTP POST. Victim telemetry was geographically broad, with observed activity across South Korea, North America, Europe, and the Middle East.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | ip-api.com | 2022-11-14 | 2026-01-21 |
| URL | http://ip-api.com/json | 2024-07-31 | 2026-01-20 |
| IPv4 | 67.203.7.171 | 2024-05-10 | 2025-11-13 |
| IPv4 | 67.203.123.171 | 2024-07-31 | 2024-10-23 |
| IPv4 | 77.37.37.81 | 2024-07-31 | 2024-10-23 |
| HASH | 63238b8d083553a8341bf6599d3d601… | 2024-07-31 | 2024-08-26 |
| HASH | bc4a082e2b999d18ef2d7de1948b2bf… | 2024-07-31 | 2024-08-26 |
| HASH | 2d10b48454537a8977affde99f6edcb… | 2024-07-31 | 2024-08-26 |
| HASH | b31f5bde1bdbc2dfd453b91bab2e9be… | 2024-07-31 | 2024-07-31 |
| HASH | eff2a9fca46425063dca08046642735… | 2024-07-31 | 2024-07-31 |
| HASH | 0639d8eaad9df842d6f358831b0d4c6… | 2024-07-31 | 2024-07-31 |
| HASH | 6263b94884726751bf4de6f1a4dc309… | 2024-07-31 | 2024-07-31 |
| HASH | 7e5828382c9ef9cd7a643bc329154a3… | 2024-07-31 | 2024-07-31 |
| URL | http://de.ztec.store:8000/www/r… | 2024-07-31 | 2024-07-31 |
| URL | http://de.ztec.store:8000 | 2024-07-31 | 2024-07-31 |
| DOMAIN | de.ztec.store | 2024-07-31 | 2024-07-31 |
Related Reports
2024-04-25 •
55% Match
Shares tags: NPM, DevPopper, T1082 • Same author: Securonix
2024-10-03 •
43% Match
#APT37
#VeilShell
#ShroudedSleep
#T1082
#T1070.004
#T1041
#T1555
#T1560
#T1112
#T1204.001
#T1059.007
#T1027
#T1204.002
#T1057
#T1566.001
#T1547.001
#T1059.001
#T1053
#T1003
#T1033
#T1132
#T1069
#T1574.014
Shares tags: T1082, T1070.004, T1041 • Same author: Securonix
2024-07-19 •
43% Match
#Trend
#Andariel
#Kimsuky
#MoonstoneSleet
#Lazarus
#T1082
#T1059.003
#T1090
#T1140
#T1005
#T1070.004
#T1041
#T1113
#T1555
#T1560
#T1071.001
#T1046
#T1112
#T1115
#T1083
#T1497
#T1056.001
#T1036
#T1027
#T1204.002
#T1566.002
#T1555.003
#T1071
#T1124
#T1222
#T1552
#T1057
#T1583.003
#T1518.001
#T1547.001
#T1053.005
#T1539
#T1608.005
#T1583.001
#T1059.001
#T1053
#T1552.001
#T1566
#T1059
#T1003
#T1497.001
#T1102.001
#T1574.002
#T1562.001
#T1490
#T1486
#T1129
#T1133
#T1571
#T1548
#T1190
#T1203
#T1564.001
#T1087
#T1562.004
#T1218.011
#T1070.006
#T1547
#T1068
#T1614
#T1573
#T1095
#T1562
#T1070
#T1047
#T1056
#T1176
#T1010
#T1033
#T1569.002
#T1543.003
#T1485
#T1012
#T1202
#T1087.002
#T1021.004
#T1222.001
#T1518
#T1564.003
#T1505.003
#T1069.002
#T1564
#T1595.002
#T1027.005
#T1070.001
#T1056.004
#T1584
Shares tags: T1082, T1059.003, T1070.004 • Published within a month
2024-05-21 •
43% Match
Analysis and Detection of CLOUD#REVERSER: An Attack Involving Threat Actors Compromising Systems Using A Sophisticated Cloud-Based Malware
Securonix
Shares tags: T1082, T1059.003, T1070.004 • Same author: Securonix
Shares tags: NPM, DevPopper • Shares 3 IOCs • Published within a month
2024-08-22 •
33% Match
#LNK
#LilithRAT
#AutoIt
#LINKON
#CURKON
#puNK-003
#puNK-002
#puNK-001
#T1059.003
#T1041
#T1204.002
#T1555.003
#T1518.001
#T1547.001
#T1053.005
#T1539
#T1059.001
#T1105
#T1571
#T1564.001
#T1027.010
#T1564.003
Shares tags: T1059.003, T1041, T1059.001 • Published within a month