Also known as: tracked as
unk_deaddrop’s campaign blended social engineering with exploitation of trusted development workflows. Attackers crafted convincing recruitment and code‑review emails that linked to actor‑controlled GitHub, GitLab or BitBucket repositories. Once a victim cloned the repository into Visual Studio Code or a compatible editor, an embedded .vscode/tasks.json silently executed a shell script that installed a malicious VSIX extension. The extension then launched a Go‑based RAT (Overlord) on macOS and Linux and a Node.js/Python pipeline on Windows. The malware conducted system reconnaissance, stole API keys, crypto wallet information, and browser credentials from Chromium‑based browsers and Firefox, and exfiltrated the data in encrypted ZIP archives to a WebSocket C2 server at 23.137.105.75:5173. The actor leveraged attacker‑controlled domains bought through Namecheap and email services such as Mailgun, Vercel, and email hosts with .xyz and .ink TLDs. Payloads were obfuscated with Base64 or AES‑256 encryption, while a self‑cleanup routine deleted cloned repositories and temporary files to reduce forensic evidence. Persistence was achieved by re‑executing the RAT if stopped and, on macOS, modifying keychain ACLs to run with elevated privileges. This operation exemplifies how modern threat actors can turn legitimate development tools into vectors for credential theft and financial gain while keeping a low profile through stealthy deployment methods.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
unk_deaddrop, an actor with probable North‑Korean ties, executed a large‑scale phishing operation in April–May 2026 that targeted software developers across finance, crypto, education and technology sectors. By using fake job offers and code‑review lures to deliver malicious GitHub repositories containing VSIX extensions and hidden task files, the group installed cross‑platform malware that stole cryptocurrency wallet credentials and browser data while maintaining persistence through deceptive editor plugins.
Goals & Targeting
The primary objective of unk_deaddrop appears to be monetisation via the acquisition of cryptocurrency wallet credentials and general developer credentials. By targeting organisations in finance, education, government, media, healthcare, retail, hospitality, and specifically within crypto‑related domains, the actor seeks both direct financial gain and potential future leverage for other operations such as ransomware or intellectual property theft. The focus on developers indicates a desire to exploit privileged access and insider information, maximizing return with minimal effort.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
unk_deaddrop ran a sustained operation between April and May 2026, targeting nearly one hundred organisations worldwide. The attacker capitalised on the trust communities built around open‑source projects and development environments, using attractive coding assignments to lure developers into cloning malicious repositories. The operational tempo was rapid: the phishing emails were mass‑distributed via email accounts on Mailgun and other services, while the delivery infrastructure (GitHub repos, Vercel hosts) allowed quick takedown evasion. Victims predominantly came from finance, crypto exchange, and education sectors—groups with valuable digital assets. Past operations by similar North‑Korean threat actors have mirrored this mix of social engineering, repository exploitation, and cryptocurrency theft.
IOC Patterns
Recommended Actions
Suggested Tags
Sources
Confidence Assessment
The analysis is based on a substantial body of publicly available intelligence from multiple reputable sources, including detailed technical reports, threat‑intel blogs, and open‑source code repositories. Confidence in the actor’s North‑Korean affiliation and use of VSIX-based delivery is high, given corroborated evidence across several publications. However, gaps remain regarding precise attribution methodology, the full extent of financial gains, and whether the campaign continued beyond May 2026. Some technical details (e.g., exact command structure inside tasks.json) are inferred from similar campaigns.
No campaigns linked yet.
No observed data linked yet.
1
Techniques
50
Tools
0
Campaigns
96
IOCs
0
Observed Data
1
Tactics