DeceptiveDevelopment is a North Korea-aligned threat actor focused on social-engineering software developers and other technical professionals through fraudulent recruiter personas and fake job opportunities. The group has been active since at least 2023 and is tracked as distinct from the Lazarus-linked Operation Dream Job activity, although some of its newer tooling shows code overlap with malware previously associated with the broader Lazarus ecosystem. The actor commonly poses as recruiters on professional networking and freelance platforms, directing targets to attacker-controlled interview or coding-test workflows. A notable technique used in these campaigns is ClickFix-style social engineering, in which victims are shown fabricated technical problems during a staged pre-interview and are instructed to copy and execute terminal commands that install malware. DeceptiveDevelopment has targeted Windows, macOS, and Linux systems, indicating a broad cross-platform capability. Malware associated with the group includes BeaverTail and its JavaScript evolution OtterCookie, which are used to steal browser credentials and cryptocurrency wallet data and to retrieve follow-on payloads. Second-stage tooling includes InvisibleFerret, a modular Python backdoor with remote-access, payload delivery, clipboard, and stealing components. Researchers have also linked Tropidoor to the actor; this payload is assessed as one of its most sophisticated tools and has code overlap with PostNapTea, a backdoor previously tied to Lazarus. Another observed payload, AkdoorTea, was delivered through a trojanized software package that blended legitimate components with malicious code. DeceptiveDevelopment has broadened targeting into cryptocurrency, blockchain, and finance-related organizations and appears to use stolen victim information in support of North Korea's fraudulent IT worker ecosystem. Reporting also links the actor operationally to a related cluster called WageMole, which poses as job seekers rather than recruiters. Overall, DeceptiveDevelopment combines initial-access social engineering with credential theft, cryptocurrency theft, modular backdoors, and persistent post-compromise access in support of financially motivated North Korean operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DeceptiveDevelopment is conducting social engineering campaigns targeting job seekers to steal data and support North Korea’s fraudulent IT worker operations. They use fake recruiter profiles and job offers to lure victims into downloading trojanized code or executing malicious commands.
DeceptiveDevelopment is a North Korean threat actor known for posing as recruiters and using fake job offers to social engineer developers into downloading malware. They target Windows, macOS, and Linux users, primarily through social engineering on LinkedIn and freelance marketplaces. Their campaigns involve staged pre-interviews and technical tests that trick victims into running malicious terminal commands, leading to credential and crypto wallet theft, and remote access.
DeceptiveDevelopment is a North Korean threat actor known for posing as recruiters and using fake job offers to social engineer developers into downloading malware. They target Windows, macOS, and Linux users, primarily through social engineering on LinkedIn and freelance marketplaces. Their campaigns involve staged pre-interviews and technical tests that trick victims into running malicious terminal commands, leading to credential and crypto wallet theft, and remote access.
North Korean group using fake job listings and social engineering to distribute malware targeting cryptocurrency, blockchain, and finance sectors.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.