Deceptive Development
2025-02-20 • ESET • DeceptiveDevelopment targets freelance developers
ESET researchers named DeceptiveDevelopment in a February 2025 report on a North Korea-aligned cluster active since at least November 2023, noting overlap with earlier public reporting under the names Contagious Interview and DEV#POPPER. Posing as recruiters on LinkedIn, Upwork, Freelancer, and crypto-focused job boards, operators lure freelance software developers, especially those in cryptocurrency and Web3 projects, into fake coding tests and interviews that deliver trojanized GitHub, GitLab, or Bitbucket repositories, or cloned video-conferencing software. Victims on Windows, Linux, and macOS are compromised chiefly to steal cryptocurrency wallets and browser-stored credentials, with a possible secondary espionage aim. Core tooling includes the BeaverTail infostealer/downloader and modular Python InvisibleFerret RAT, later joined by OtterCookie, the multiplatform WeaselStore infostealer, the TsunamiKit toolkit, and more advanced backdoors such as Tropidoor and AkdoorTea that share code with malware linked to Lazarus. Subsequent reporting documented added ClickFix social-engineering lures, abuse of IDE task-runner files in VS Code and Cursor for delivery, and information-sharing ties to North Korean fraudulent IT-worker schemes tracked separately as WageMole.
-
28
Related Actors
-
5
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster