UNK_Dead Drop
2026-06-08 • Proofpoint • Don't Fear the Repo: UNK_DeadDrop Phishing Campai…
UNK_DeadDrop is Proofpoint's designation for a likely North Korea-aligned phishing cluster documented in a June 2026 report on campaigns observed between April and May 2026 that targeted developers at close to 100 organizations across finance, cryptocurrency, education, technology, and business-services sectors, sending over 250 emails in about six weeks, mostly to US-based targets. The campaign used recruitment, technical-assignment, code-review, Foundry-testing, and AI-payment-themed lures directing victims to actor-controlled GitHub and GitLab repositories built around realistic project themes; opening these projects in Visual Studio Code or Cursor silently triggered a hidden task that installed a malicious extension and, on Linux and macOS, deployed Go-based malware built on the open-source Overlord command-and-control framework, while Windows victims received a JavaScript and Python payload chain run inside the editor's own process. The malware stole cryptocurrency wallets, browser credentials, and OS keychain or keyring data, exfiltrating it as ZIP archives before cleaning up traces. Proofpoint assessed the cluster shares targeting and tradecraft with Contagious Interview but tracks it separately given distinct initial access, campaign volume, and infrastructure.
-
28
Related Actors
-
1
Related Reports
Related Actors
Related Reports
Top Authors
View all reports in this cluster