Threat Advisory

DEVPOPPER Malware Campaign Expands to Windows, Linux, macOS Targeting Developers

Threat: Malware
Targeted Region: South Korea, North America, Europe & the Middle East
Threat Actor Region: North Korea
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The DEV#POPPER campaign, attributed to North Korean threat actors, has evolved to target developers with new malware variants and tactics. These attacks now support multiple operating systems, including Linux, Windows, and macOS. The primary goal remains to exploit social engineering tactics to compromise software developers, leading to widespread impact across South Korea, North America, Europe, and the Middle East.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

The DEV#POPPER campaign, attributed to North Korean threat actors, has evolved to target developers with new malware variants and tactics. These attacks now support multiple operating systems, including Linux, Windows, and macOS. The primary goal remains to exploit social engineering tactics to compromise software developers, leading to widespread impact across South Korea, North America, Europe, and the Middle East.[emaillocker id="1283"]

 

The DEV#POPPER campaign employs techniques to deliver malware through seemingly innocuous ZIP file packages presented during fake job interviews. The malicious code is deeply embedded within JavaScript files and heavily obfuscated, making detection challenging. Upon execution, the malware initiates an infection chain that includes dynamic payload downloads, system information exfiltration, and remote command execution. The campaign's new capabilities include enhanced obfuscation, robust data exfiltration via FTP, and the use of AnyDesk for persistence. The malware targets multiple operating systems, adapting its payloads to the specific environment, and leverages both HTTP and FTP for communication with command and control (C2) servers.

 

In conclusion, the DEV#POPPER campaign exemplifies the persistent and evolving nature of advanced threats. By targeting industry professionals through social engineering tactics and leveraging cross-platform malware, the threat actors demonstrate a high level of dedication and technical prowess. Mitigation strategies should focus on educating potential victims about social engineering tactics, enhancing detection mechanisms for obfuscated code, and implementing robust endpoint security measures to counter these attacks.

THREAT PROFILE:

Tactic Technique Id Technique
Execution T1059 Command and Scripting Interpreter
Defense Evasion  T1027 Obfuscated Files or Information
T1070 Indicator Removal
Discovery T1033 System Owner/User Discovery
 T1082 System Information Discovery
Collection T1560 Archive Collected Data
Command and Control T1132 Data Encoding
Exfiltration T1041 Exfiltration Over C2 Channel

REFERENCES:

The following reports contain further technical details:
https://thehackernews.com/2024/07/north-korea-linked-malware-targets.html

[/emaillocker]
crossmenu