A group of activities seemingly linked to North Korea and monitored by ESET under the name DeceptiveDevelopment is siphoning funds from victims’ digital wallets and pilfering their access credentials from internet browsers and password storage tools
20 Feb 2025
Researchers from ESET have detected a deceitful scheme in which threat actors aligned with North Korea, posing as recruitment specialists, are aiming at independent software developers with information-stealing malicious software.
The operations, dubbed as DeceptiveDevelopment and dating back to at least November 2023, involve targeted phishing messages circulated on platforms for job searches and freelancing, urging the recipients to complete a programming evaluation. The required files for the assignment are generally stored on restricted repositories like GitHub. Unfortunately, these files contain malware that ultimately enables the attackers to abscond with the victims’ access credentials and empty their digital currency wallets.
For a deeper insight into the strategies, methods, and practices of this campaign, watch the video featuring ESET’s Chief Security Evangelist Tony Anscombe and ensure to peruse the entire blogpost.

