Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack
2026-09-09 • Mal Beacon •
https://blog.deception.pro/blog/hok-dprk-polinrider-sep-2026
A live operator compromised an instrumented decoy workstation through a trojanized PyPI package and fake coding assignment, producing activity assessed as consistent with the DPRK-linked PolinRider campaign. The operator deployed JavaScript and Python payloads, accessed LSASS, installed Python as SYSTEM, and established three persistence mechanisms disguised as Microsoft .NET optimization components. Collection capabilities included credential, clipboard, screen, source-code, and cryptocurrency-wallet theft, with data exfiltrated to a public IP over port 8443. The lure, tooling, and reused infrastructure linked the intrusion to the wider Contagious Interview and Famous Chollima ecosystem with moderate confidence.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | bc866cfcdda37e24dc2634dc282c7a0… | 2026-09-09 | 2026-09-09 |
| HASH | c197268f7e7cf2848b8c1ae59bbd0e0… | 2026-09-09 | 2026-09-09 |
| HASH | d4688428d0e99fd4f0320d14fdd6ed4… | 2026-09-09 | 2026-09-09 |
| HASH | 7c4029b7f1383e25fb1b1ed10292e0b… | 2026-09-09 | 2026-09-09 |
| HASH | 75ad8365fce771294258a792fcd6b92… | 2026-09-09 | 2026-09-09 |
| URL | https://gitlab.com/test26330331… | 2026-09-09 | 2026-09-09 |
| IPv4 | 150.251.113.223 | 2026-09-09 | 2026-09-09 |
| IPv4 | 23.27.13.135 | 2026-09-02 | 2026-09-09 |
| DOMAIN | files.catbox.moe | 2025-06-03 | 2026-09-09 |