Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack

2026-09-09 Mal Beacon

https://blog.deception.pro/blog/hok-dprk-polinrider-sep-2026

Thumbnail for Hands-on-Keyboard Activity from the DPRK "PolinRider" Supply Chain Attack

A live operator compromised an instrumented decoy workstation through a trojanized PyPI package and fake coding assignment, producing activity assessed as consistent with the DPRK-linked PolinRider campaign. The operator deployed JavaScript and Python payloads, accessed LSASS, installed Python as SYSTEM, and established three persistence mechanisms disguised as Microsoft .NET optimization components. Collection capabilities included credential, clipboard, screen, source-code, and cryptocurrency-wallet theft, with data exfiltrated to a public IP over port 8443. The lure, tooling, and reused infrastructure linked the intrusion to the wider Contagious Interview and Famous Chollima ecosystem with moderate confidence.

Indicators of Compromise

Type Value First Seen Last Seen
HASH bc866cfcdda37e24dc2634dc282c7a0… 2026-09-09 2026-09-09
HASH c197268f7e7cf2848b8c1ae59bbd0e0… 2026-09-09 2026-09-09
HASH d4688428d0e99fd4f0320d14fdd6ed4… 2026-09-09 2026-09-09
HASH 7c4029b7f1383e25fb1b1ed10292e0b… 2026-09-09 2026-09-09
HASH 75ad8365fce771294258a792fcd6b92… 2026-09-09 2026-09-09
URL https://gitlab.com/test26330331… 2026-09-09 2026-09-09
IPv4 150.251.113.223 2026-09-09 2026-09-09
IPv4 23.27.13.135 2026-09-02 2026-09-09
DOMAIN files.catbox.moe 2025-06-03 2026-09-09

Related Actors

Related Reports

« Back