#CovertCatch
Malware/Tool
2024-09-03 • DeFied Expectations — Examining Web3 Heists
COVERTCATCH is malware used by a DPRK threat actor in a cryptocurrency heist investigation. The actor approached an engineer on LinkedIn with a fake job opportunity and, after an initial conversation, sent a ZIP archive containing the malware disguised as a Python coding challenge. Execution compromised the engineer’s macOS system by downloading second-stage malware. That subsequent malware established persistence through Launch Agents and Launch Daemons. The activity illustrates a developer-focused social-engineering method observed in Web3 targeting, where fraudulent recruiting and coding tests serve as the initial infection vector before additional malware is installed on the victim’s system.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days