Analysis of DEV#POPPER: New Attack Campaign Targeting Software Developers Likely Associated With North Korean Threat Actors
2024-04-25 • Securonix •
Securonix tracks DEV#POPPER as an ongoing social engineering campaign likely tied to North Korean threat actors and aimed at software developers. Attackers pose as interviewers, send GitHub-hosted coding tasks, and rely on the target running a malicious NPM package during the fake interview process. The first-stage JavaScript downloads an archive from 147.124.214[.]131:1244, extracts a hidden Python payload, and runs follow-on Python code that contains hard-coded C2 infrastructure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 147.124.214.131 | 2024-04-25 | 2026-09-21 |
| IPv4 | 173.211.106.101 | 2024-04-25 | 2025-07-26 |
| HASH | 33617f0ac01a0f7fa5f64bd8edef737… | 2024-04-25 | 2024-08-26 |
| HASH | 45c991529a421104f2edf03d92e01d9… | 2024-04-25 | 2024-05-10 |
| HASH | 977a9024962102b02128d391c0543c6… | 2024-04-25 | 2024-04-25 |
| HASH | f9ca12321fb91157cce8513e935810d… | 2024-04-25 | 2024-04-25 |
Related Reports
2024-07-31 •
55% Match
Shares tags: NPM, DevPopper, T1082 • Same author: Securonix
2024-05-21 •
53% Match
Analysis and Detection of CLOUD#REVERSER: An Attack Involving Threat Actors Compromising Systems Using A Sophisticated Cloud-Based Malware
Securonix
Shares tags: T1082, T1059.003, T1070.004 • Same author: Securonix • Published within a month
Shares 3 IOCs • Published within a month
2024-10-03 •
38% Match
#APT37
#VeilShell
#ShroudedSleep
#T1082
#T1070.004
#T1041
#T1555
#T1560
#T1112
#T1204.001
#T1059.007
#T1027
#T1204.002
#T1057
#T1566.001
#T1547.001
#T1059.001
#T1053
#T1003
#T1033
#T1132
#T1069
#T1574.014
Shares tags: T1082, T1070.004, T1041 • Same author: Securonix
2024-04-03 •
36% Match
#RokRAT
#LNK
#T1102.002
#T1082
#T1059.003
#T1005
#T1113
#T1083
#T1204.002
#T1566.001
#T1059.001
#T1055
#T1622
#T1027.010
#T1106
#T1027.009
#T1033
Shares tags: T1082, T1059.003, T1059.001 • Published within a month
2024-03-18 •
36% Match
Analysis of New DEEP#GOSU Attack Campaign Likely Associated with North Korean Kimsuky Targeting Victims with Stealthy Malware
Securonix
Shares tags: T1082, T1070.004, T1041 • Same author: Securonix