Void Dokkaebi

2025-04-23 • Trend MicroRussian Infrastructure Plays Crucial Role in Nort…

Trend Micro tracks Void Dokkaebi, also known as Famous Chollima, as a North Korea-aligned intrusion set that targets software developers and IT professionals with interests in cryptocurrency, Web3, and blockchain technology through fake recruiter job-interview lures on platforms such as LinkedIn, including through the fictitious company BlockNovas, whose domain was seized by the FBI in April 2025 after its automated interview process delivered Beavertail and Invisible Ferret-family malware. Void Dokkaebi's operations are partly routed through anonymization layers built on Russian IP ranges near the North Korean border, used alongside North Korean IT workers embedded abroad, and its primary objective is cryptocurrency theft, with occasional pivots to espionage when initial access does not yield stealable funds. A subsequent campaign showed the group evolving into a self-propagating supply chain threat: compromised developers' repositories were weaponized with auto-running VS Code task configurations and obfuscated, git history-tampering JavaScript injections that retrieved payloads including a DEV#POPPER RAT variant via blockchain transactions, infecting more than 750 public repositories and reaching organizational codebases.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster