North Korea’s Crypt: Hunting Ghosts
2026-08-21 • Bitso •
https://quetzal.bitso.com/p/north-koreas-crypt-hunting-ghosts
A DPRK-linked fake recruiter sent a Bitso developer a malicious coding challenge containing cross-platform PowerShell and Bash stagers. The scripts created a hidden `.vscode` directory, inspected or updated Node.js, and installed a previously unseen obfuscated JavaScript payload named `ghost.js` or `ghost.npl`. The payload collected host, platform, IP, and MAC information and registered victims with a C2 server using an address, endpoint, and communication key embedded as Base64 strings. Quetzal found that the registration interface lacked adequate access controls, allowing repeated synthetic victim registrations to pollute the attackers’ infrastructure.