Hexagonal Rodent
2026-04-22 • Expel • Inside Lazarus: How North Korea uses AI to indust…
Expel first identified and named this group in April 2026, introducing it as Expel-TA-0001, also known as HexagonalRodent, an activity cluster it assesses with high confidence to be North Korean, DPRK, state-sponsored, likely a subgroup or spin-off of a larger organization, and with medium-high confidence a subset of the cluster CrowdStrike tracks as Famous Chollima. The group is financially motivated, targeting Web3 and cryptocurrency developers through fake recruiter outreach and job offers on LinkedIn and fake company websites, delivering backdoored coding skills assessments that execute the BeaverTail, OtterCookie, and InvisibleFerret malware to steal browser, keychain, and cryptocurrency wallet credentials. It has also conducted at least one software supply-chain compromise. The group makes heavy use of generative AI tools to build malware, fake personas, and websites, and internal panel data indicated a structure of roughly thirty-one operators across six teams. Over a three-month period it exfiltrated an estimated twelve million dollars in cryptocurrency from more than 2,700 compromised systems.
-
28
Related Actors
-
2
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster