#CovertCatch

Malware/Tool

2024-09-03 • DeFied Expectations — Examining Web3 Heists

COVERTCATCH is malware used by a DPRK threat actor in a cryptocurrency heist investigation. The actor approached an engineer on LinkedIn with a fake job opportunity and, after an initial conversation, sent a ZIP archive containing the malware disguised as a Python coding challenge. Execution compromised the engineer’s macOS system by downloading second-stage malware. That subsequent malware established persistence through Launch Agents and Launch Daemons. The activity illustrates a developer-focused social-engineering method observed in Web3 targeting, where fraudulent recruiting and coding tests serve as the initial infection vector before additional malware is installed on the victim’s system.

Tagged Reports

« Back