North Korea-aligned threat actors, tracked as DeceptiveDevelopment or Contagious Interview, have intensified campaigns targeting software developers in the cryptocurrency and Web3 sectors. These attackers use fake recruiter profiles and staged job interviews to deliver trojanized codebases and malware, including infostealers like BeaverTail, OtterCookie, WeaselStore, and the modular remote access tool InvisibleFerret. Recent research also uncovered a new backdoor, AkdoorTea, and additional tools such as TsunamiKit and Tropidoor, all deployed through sophisticated social engineering tactics across Windows, Linux, and macOS platforms. The group leverages platforms like LinkedIn, Upwork, and GitHub to lure victims, often instructing them to execute malicious scripts under the guise of coding assessments or technical troubleshooting. ESET's analysis links these operations to North Korean IT workers involved in fraudulent job schemes, highlighting the group's financial motives and broad operational scale.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
On October 16, 2025, Google Cloud's Mandiant reported that a DPRK-linked developer-targeting campaign had adopted the JavaScript malware family JADESNOW to fetch encrypted payloads from Ethereum and BNB Smart Chain smart contracts using EtherHiding. The report said the infection chain could culminate in the Python backdoor INVISIBLEFERRET for high-value targets, extending fake recruiter and interview lures across Windows, macOS, and Linux.
The U.S. Department of Justice announced coordinated actions across 16 states targeting North Korean remote IT-worker schemes, including indictments, an arrest, and asset seizures. The action was cited alongside reporting on DeceptiveDevelopment and related WageMole activity.
ESET reported that Tropidoor shares substantial code with Lazarus-associated PostNapTea, and that other tooling overlaps suggest DeceptiveDevelopment has access to more advanced North Korean malware capabilities. The company also linked the campaign operationally to the broader fake IT-worker ecosystem, including WageMole.
On September 25, 2025, ESET publicly reported that DeceptiveDevelopment had expanded its malware arsenal with newly documented payloads including AkdoorTea, Tropidoor, and TsunamiKit. The researchers said the campaign used fake job and coding-assessment lures to infect developers and steal credentials, browser data, and cryptocurrency wallet information.
In September 2025, Ransom-ISAC investigated a fake job social-engineering attack that used a malicious private GitHub repository impersonating a legitimate project to target a developer. The malware used a novel multi-blockchain command-and-control technique dubbed Cross-Chain TxDataHiding, retrieving encrypted payloads via TRON or Aptos pointers to Binance Smart Chain transaction data before deploying a NodeJS RAT and Python stealer.
ESET telemetry indicated that ClickFix attacks increased by more than 500% in the first half of 2025. The technique was used in DeceptiveDevelopment's fake interview lures to trick victims into running terminal commands that downloaded malware.
On 2024-09-03, the FBI and IC3 issued a public warning that North Korean actors were aggressively targeting cryptocurrency and related organizations with well-disguised social-engineering attacks. The alert described fake recruiting and outreach tactics consistent with the broader developer-targeting activity later documented as part of DeceptiveDevelopment.
On April 24, 2024, Securonix published research on the DEV#POPPER campaign, which used fake job interviews and malicious GitHub-hosted Node.js projects to infect software developers. The report linked the activity to likely North Korean threat actors and described Python-based follow-on payloads that enabled reconnaissance, remote access, file theft, clipboard capture, and keylogging.
ESET said the North Korea-aligned DeceptiveDevelopment operation has been active since at least 2023, using fake recruiter personas and bogus interview processes to target software developers, especially in cryptocurrency and Web3. The campaign delivered malware such as BeaverTail and InvisibleFerret across Windows, Linux, and macOS.
On 2022-08-17, reporting described North Korean threat actors targeting job seekers through fake employment-themed lures and delivering macOS malware. The activity showed early use of recruiter-style social engineering later associated with broader developer-targeting campaigns.
The reporting notes that PostNapTea, a backdoor later found to share code with Tropidoor, had previously been used against South Korean targets in 2022. This historical overlap helped support later assessments of tooling links between DeceptiveDevelopment and Lazarus-associated malware.
19 references tracked. Mallory keeps watching after this page renders.
allsecure.io
Open sourceransom-isac.org
Open sourcecloud.google.com
Open sourcegovinfosecurity.com
Open sourcethehackernews.com
Open sourceapp.tidalcyber.com
Open sourceptsecurity.com
Open sourcevirusbulletin.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.