Research Update: Threat Actors Behind the DEV#POPPER Campaign Have Retooled and are Continuing to Target Software Developers via Social Engineering

2024-07-31 Securonix

https://www.securonix.com/blog/research-update-threat-actors-behind-the-devpopper-campaign-have-retooled-and-are-continuing-to-target-software-developers-via-social-engineering/

Thumbnail for Research Update: Threat Actors Behind the DEV#POPPER Campaign Have Retooled and are Continuing to Target Software Developers via Social Engineering

Securonix reports that the North Korea-linked DEV#POPPER operators continued targeting software developers with fake interview lures and a ZIP package containing hidden malicious JavaScript. The updated samples added support for Windows, Linux, and macOS, with obfuscated code that decodes a C2 endpoint at 67.203.7[.]171:1244. The malware identifies the host platform, builds paths and variables for each operating system, collects system information, and sends the data to the remote server over HTTP POST. Victim telemetry was geographically broad, with observed activity across South Korea, North America, Europe, and the Middle East.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN ip-api.com 2022-11-14 2026-01-21
URL http://ip-api.com/json 2024-07-31 2026-01-20
IPv4 67.203.7.171 2024-05-10 2025-11-13
IPv4 67.203.123.171 2024-07-31 2024-10-23
IPv4 77.37.37.81 2024-07-31 2024-10-23
HASH 63238b8d083553a8341bf6599d3d601… 2024-07-31 2024-08-26
HASH bc4a082e2b999d18ef2d7de1948b2bf… 2024-07-31 2024-08-26
HASH 2d10b48454537a8977affde99f6edcb… 2024-07-31 2024-08-26
HASH b31f5bde1bdbc2dfd453b91bab2e9be… 2024-07-31 2024-07-31
HASH eff2a9fca46425063dca08046642735… 2024-07-31 2024-07-31
HASH 0639d8eaad9df842d6f358831b0d4c6… 2024-07-31 2024-07-31
HASH 6263b94884726751bf4de6f1a4dc309… 2024-07-31 2024-07-31
HASH 7e5828382c9ef9cd7a643bc329154a3… 2024-07-31 2024-07-31
URL http://de.ztec.store:8000/www/r… 2024-07-31 2024-07-31
URL http://de.ztec.store:8000 2024-07-31 2024-07-31
DOMAIN de.ztec.store 2024-07-31 2024-07-31

Related Reports

2024-07-19 • 43% Match
#Trend #Andariel #Kimsuky #MoonstoneSleet #Lazarus #T1082 #T1059.003 #T1090 #T1140 #T1005 #T1070.004 #T1041 #T1113 #T1555 #T1560 #T1071.001 #T1046 #T1112 #T1115 #T1083 #T1497 #T1056.001 #T1036 #T1027 #T1204.002 #T1566.002 #T1555.003 #T1071 #T1124 #T1222 #T1552 #T1057 #T1583.003 #T1518.001 #T1547.001 #T1053.005 #T1539 #T1608.005 #T1583.001 #T1059.001 #T1053 #T1552.001 #T1566 #T1059 #T1003 #T1497.001 #T1102.001 #T1574.002 #T1562.001 #T1490 #T1486 #T1129 #T1133 #T1571 #T1548 #T1190 #T1203 #T1564.001 #T1087 #T1562.004 #T1218.011 #T1070.006 #T1547 #T1068 #T1614 #T1573 #T1095 #T1562 #T1070 #T1047 #T1056 #T1176 #T1010 #T1033 #T1569.002 #T1543.003 #T1485 #T1012 #T1202 #T1087.002 #T1021.004 #T1222.001 #T1518 #T1564.003 #T1505.003 #T1069.002 #T1564 #T1595.002 #T1027.005 #T1070.001 #T1056.004 #T1584
Shares tags: T1082, T1059.003, T1070.004 • Published within a month
« Back