UNK_DeadDrop is a likely North Korea-aligned threat cluster focused on software developers, particularly those connected to cryptocurrency and decentralized-finance ecosystems. The activity has been associated with phishing campaigns that used fake job offers, recruiter outreach, code-review requests, and technical testing themes to lure victims into cloning attacker-controlled repositories and opening them in development environments such as Visual Studio Code and Cursor. The cluster has shown similarities to the DPRK-linked Contagious Interview activity, but has been tracked separately due to distinct delivery patterns, infrastructure, scale, and payload implementation. The actor primarily targets organizations in the United States and has affected technology, financial services, education, business services, telecommunications, and media-related organizations, with particular emphasis on cryptocurrency firms. Its operations rely on social engineering and abuse of normal developer workflows. Malicious repositories contain hidden task automation that triggers code execution when a project folder is opened, and the infection chain installs a rogue VS Code extension for persistence on macOS and Linux. UNK_DeadDrop uses cross-platform malware for macOS, Linux, and Windows. On macOS and Linux, the actor has deployed a Go-based remote access trojan derived from the open-source Overlord framework, maintaining persistence and command-and-control connectivity through the malicious editor extension. On Windows, the actor has used an in-memory JavaScript and Python-based infostealer chain executed within the editor process, generally without persistence. Across platforms, the malware is designed for credential theft, browser data theft, cookie theft, cryptocurrency wallet theft, and exfiltration of sensitive artifacts. It has targeted browser-stored credentials and cookies, browser wallet extensions, and standalone wallet applications. On macOS and Linux, the malware has also used fake password prompts to capture the user’s system password and then access protected secrets such as Keychain or GNOME Keyring data. On Windows, it has used techniques to bypass Chromium credential protections. Observed tradecraft includes phishing-based initial access, credential theft, session theft via browser cookies, persistence through malicious extensions, post-exploitation collection, exfiltration, and defense evasion through cleanup of dropped artifacts. The actor’s behavior and victimology are consistent with financially motivated North Korean operations that seek to steal cryptocurrency and credentials from developer environments.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
124 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Abused developer platforms and tools to steal credentials and cryptocurrency wallets from developers.
A North Korea-aligned activity cluster targeting developers with phishing emails that impersonate recruiters or code reviewers and direct victims to malicious GitHub/GitLab repositories. The campaign abuses hidden VS Code task automation to execute malware, establish persistence, steal credentials, exfiltrate browser data, and drain cryptocurrency wallets across macOS, Linux, and Windows.
Targets developers with fake job offers and coding assignments delivered by email, leading to deployment of cross-platform malware for cryptocurrency wallet theft and credential theft.
Phishing software developers with fake job and code-review lures that direct victims to malicious GitHub or GitLab repositories, with the goal of stealing cryptocurrency wallets, credentials, browser data, and protected secrets across Windows, macOS, and Linux.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.