#Willo
Incident/Operation
2025-04-22 • Analysis of TraderTraitor’s GopherGrabber Malware observed by Willo Campaign
The Willo Campaign is a North Korean-linked TraderTraitor operation that has distributed the multiplatform GopherGrabber backdoor and stealer since 2024. It began with malicious packages in the official NPM repository in June, shifted to a trojanized service installer in July, and from December used LinkedIn job offers and fake video-interview pages to trick cryptocurrency-industry developers and sales managers into running malicious commands. GopherGrabber was delivered as a Go project and used encrypted HTTP communications to provide backdoor and information-stealing functions.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days