UNK_DeadDrop is a threat activity cluster tracked by Proofpoint that targets software developers to steal credentials and cryptocurrency assets. During April and May 2026, it sent more than 250 phishing emails to individuals at nearly 100 organizations, predominantly in the United States. Targeted sectors included cryptocurrency and financial services, technology, education, business services, media, and telecommunications. Its tradecraft overlaps with the North Korea-linked Contagious Interview campaign, but it is tracked independently because of differences in delivery methods, infrastructure, and payload implementation; attribution to an established threat group remains unconfirmed. The cluster uses fabricated recruitment opportunities, code-review requests, and cryptocurrency project testing assignments to direct victims to attacker-controlled GitHub and GitLab repositories. It impersonates legitimate companies and creates fictitious startup identities. Malicious repositories abuse task automation in Visual Studio Code and Cursor to execute platform-specific payloads when a project is opened. Visual Studio Code requires trust and task approval, whereas observed Cursor execution occurred without those prompts. On macOS and Linux, the infection chain deploys modified Go-based remote access malware derived from the open-source Overlord framework. A malicious editor extension masquerading as a Google service provides persistence by relaunching the malware when the editor starts. On Windows, JavaScript and Python components execute through the editor's Electron environment to perform a single theft operation without equivalent persistence. The malware collects browser passwords, cookies, cryptocurrency wallet extensions, standalone wallet data, and protected browser secrets. On macOS and Linux, fake system password dialogs capture credentials that are subsequently used for privileged execution and extraction of Keychain or GNOME Keyring secrets. Windows payloads bypass Chromium App-Bound Encryption. Stolen information is archived and exfiltrated, and cleanup routines remove artifacts to impede investigation.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
124 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A suspected North Korea-aligned threat cluster mentioned as a tactical comparison for a separate macOS campaign involving a fake Zoom installer. The reference does not establish its involvement in MALFEX or directly attribute the separate campaign to this cluster.
Abused developer platforms and tools to steal credentials and cryptocurrency wallets from developers.
A North Korea-aligned activity cluster targeting developers with phishing emails that impersonate recruiters or code reviewers and direct victims to malicious GitHub/GitLab repositories. The campaign abuses hidden VS Code task automation to execute malware, establish persistence, steal credentials, exfiltrate browser data, and drain cryptocurrency wallets across macOS, Linux, and Windows.
Targets developers with fake job offers and coding assignments delivered by email, leading to deployment of cross-platform malware for cryptocurrency wallet theft and credential theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.