HexagonalRodent, also tracked as Expel-TA-0001, is a North Korean state-sponsored and financially motivated threat cluster focused on cryptocurrency theft, particularly against Web3 and DeFi developers. The activity overlaps with the cluster tracked by CrowdStrike as Famous Chollima and is widely assessed as part of the broader Lazarus ecosystem; some reporting further places it within the TraderTraitor lineage. The group is notable for high-volume targeting of individual developers rather than concentrating primarily on major exchanges. HexagonalRodent commonly uses employment-themed social engineering, posing as recruiters or legitimate companies and delivering fake job offers, fraudulent interviews, and backdoored coding assessments. The operation has used fabricated corporate personas, fake websites, and synthetic professional profiles to support these lures, including AI-assisted identity creation and website generation. Malware delivery has included malicious project files and abuse of developer tooling behavior, including automatic task execution in Visual Studio Code when a project folder is opened, as well as embedded backdoors that execute when assessment code is run normally. The group has been linked to BeaverTail, OtterCookie, and InvisibleFerret. Reported functionality includes credential theft from browsers and password stores, reverse-shell access, ongoing remote control, and theft of cryptocurrency wallet data followed by wallet draining. Malware is frequently written in NodeJS and Python, which helps it blend into normal developer environments, and JavaScript payloads have been obfuscated to complicate detection. Reporting also indicates at least one supply-chain compromise involving a developer extension used to distribute malware, suggesting expansion beyond direct social-engineering delivery. HexagonalRodent has made extensive operational use of commercial generative AI tools to improve productivity in malware development, infrastructure support, social engineering, fake-company creation, and code auditing intended to make malicious assessments less likely to be flagged. Investigations into exposed operator infrastructure indicated a structured, multi-team operation with dedicated workflows for credential theft, remote access, file management, and wallet processing. Observed campaigns in early 2026 reportedly compromised thousands of developer systems and exfiltrated tens of thousands of cryptocurrency wallets, with associated crypto assets valued at roughly $12 million. The actor’s dominant objective is financial gain in support of DPRK-linked cryptocurrency theft operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DPRK-aligned group targeting Web3 developers through fake job offers and backdoored coding assessments, using AI-generated personas and AI tools to improve social engineering and sustain fraudulent remote engineering roles for source code, signing key, credential, and cryptocurrency theft.
Runs an active campaign targeting software developers, especially Web3 developers, through fake job interviews and malicious coding tests to steal cryptocurrency and NFTs. The group also conducted a supply chain attack via a compromised VSCode extension.
Cryptocurrency theft campaign targeting Web3 developers through fake LinkedIn job offers and malicious coding assessment tools that deploy credential-stealing malware.
Targets individual Web3 developers through fake job offers, fake company websites, and malicious coding assessments to deploy malware and steal cryptocurrency wallet data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.