LW22: Developer lures, stolen build access, and persistent control
Executive Summary
Last week’s reports kept developers and cryptocurrency organizations at the center of DPRK-linked activity. Fake recruiting, malicious editor tasks, compromised package branches, npm payloads, fake conferencing updates, and stolen development credentials all created paths from a single workstation into code distribution and financial systems.
Kimsuky and TA406 continued to pair tailored phishing with scripts, newly disclosed vulnerabilities, legitimate cloud services, and remote-access tooling. RemotePE supplied a separate model for long-lived access in finance, while broader reporting connected developer compromise to DeFi theft and supply chain operations. One infrastructure observation inside DPRK address space remained exploratory rather than a confirmed intrusion campaign.
Key Trends
1. Developer lures crossed package and editor boundaries
A smart-contract security developer received a fake recruiting email that led to a GitLab repository whose VS Code task installed a malicious extension and native Go implants.1 A compromised Packagist development branch used a JavaScript loader and multi-blockchain dead drop in a likely Famous Chollima coding-task lure.2 SafeDep’s MicrosoftSystem64 analysis found a cross-platform npm RAT that stole browser, wallet, Telegram, SSH, clipboard, and screen data while using Hugging Face for exfiltration.3
Sapphire Sleet used a fake Zoom SDK update against macOS users in venture capital, Web3, and cryptocurrency organizations, followed by password prompts, TCC abuse, LaunchDaemon persistence, and an in-memory beacon.4 Across these cases, ordinary developer and meeting workflows provided the execution path.
2. Stolen development access enabled downstream compromise
Wiz tracked JINX-0164 using recruiter lures and AUDIOFIX to steal wallet, cloud, GitHub, and CI/CD secrets before compromising software distribution and trojanizing @velora-dex/sdk.5 A separate analysis described the same cluster as North Korea-linked, but the original Wiz assessment found behavioral similarities without infrastructure overlap and did not attribute it to a state sponsor.6 The stronger conclusion is that JINX-0164 poses a directly relevant adjacent threat to the same cryptocurrency development environment.
RemotePE showed how Lazarus-linked access could persist after entry through memory-only execution, encrypted C2, plugin loading, and EDR evasion.7 A monthly incident review placed these techniques beside the Drift Protocol and KelpDAO thefts and the Axios supply chain compromise.8 ESET’s multi-month review likewise covered the Axios intrusion, developer targeting, cryptocurrency operations, and activity by Andariel and ScarCruft.9
3. Kimsuky and TA406 reused phishing foundations with newer components
Proofpoint observed TA406 chaining two Office and Windows vulnerabilities in diplomatic-themed RTF lures before retrieving and executing a DLL payload.10 ENKI published English and Korean analyses of Kimsuky campaigns that used fake security software and Webex pages, JSONPing localhost checks, and a new in-memory HttpSpy variant.1112
A card-company secure-mail lure used LNK, PowerShell, mshta, obfuscated VBScript, Google Drive, and payloads for backdoor access and information theft.13 AhnLab’s April review placed similar LNK and script chains across South Korea-focused spear-phishing activity.14 Hauri’s KimjongRAT variant added Telegram and Discord collection and installed a MeshCentral agent, shifting the chain toward persistent remote control.15
4. Infrastructure labels can hide wider campaign roles
An investigation of a server first labeled as FTP infrastructure later connected it to OtterCookie-related collection, a reminder that one observed service may reveal only part of a campaign host’s purpose.16 Separately, NK Internet observed a captive portal framework under test in DPRK IP space, including connectivity checks, Korean comments, and a Huawei-themed WiFi error page.17
The captive portal finding supports monitoring, but it does not by itself establish a deployed phishing or access operation. Infrastructure purpose should be revised as new services and traffic become visible.
What to Watch
Treat repositories, package branches, editor tasks, conferencing updates, and development credentials as a connected attack surface. For Kimsuky and TA406 activity, correlate document and LNK delivery with localhost callbacks, script interpreters, cloud-hosted payloads, scheduled tasks, and newly installed remote-management agents.
Reports Reviewed
I was likely targeted by DPRK in a sophisticated developer malware campaign ↩︎
Famous Chollima Targets PHP Developers Through Compromised Packagist Package ↩︎
Inside MicrosoftSystem64: A Supply Chain RAT Exfiltrating to HuggingFace ↩︎
Sapphire Sleet Targets macOS in Multi-Stage Intrusion Campaign ↩︎
Commit to Compromise: A New Threat Actor Targeting the Cryptocurrency Industry’s Software Development Infrastructure ↩︎
JINX-0164 Cryptocurrency Malware: AUDIOFIX Wallet Theft (2026) ↩︎
Lazarus Expands Financial Espionage Operations With Memory-Resident RemotePE RAT ↩︎
April 2026: ShinyHunters Hits Medtronic and ADT as North Korean Hackers Drain DeFi Protocols ↩︎
More CVEs, Same Playbook: 2026 Vulnerability Exploitation in the Wild ↩︎
Kimsuky’s Advanced Attack Techniques: JSONPing, Webex Spoofing, and a New HttpSpy Variant ↩︎
Kimsuky의 고도화된 공격 기법 분석: JSONPing, Webex 사칭, 그리고 새로운 HttpSpy 변종 ↩︎
the FTP Server: How One Boring Label Hid a Second Layer of the Campaign ↩︎