HexagonalRodent, also tracked by Expel as Expel-TA-0001, is a financially motivated, state-sponsored North Korean (DPRK) threat group focused primarily on stealing cryptocurrency and NFTs from Web3 and DeFi developers. Expel assesses it as a subgroup, operational offshoot, or spin-off overlapping with CrowdStrike’s Famous Chollima; the activity is also described by other vendors as Contagious Interview, and reporting places it within the broader Lazarus ecosystem. The group targets software developers globally using employment-themed social engineering. It poses as recruiters or fake companies on LinkedIn and Web3-focused job platforms, creates fake company websites and employee personas, and lures victims with fraudulent remote job opportunities and malicious coding assessments. Those assessments deliver malware through backdoored project code and abuse of VSCode tasks.json configured with runOn:"folderOpen" so malware executes when a project folder is opened; embedded malicious functions provide a secondary execution path when the code is run normally. HexagonalRodent has been linked to BeaverTail, OtterCookie, and InvisibleFerret malware. BeaverTail is used for credential theft, including from browser password managers, macOS Keychain, Linux Keyring, and 1Password. OtterCookie and InvisibleFerret provide reverse-shell or ongoing remote-access capability. The malware is written in NodeJS and Python and uses obfuscated JavaScript to blend into normal developer environments and complicate detection. Expel reported that the group makes significant use of generative AI tools including ChatGPT, Cursor, and Anima to support malware development, fake website creation, recruiter and company persona generation, infrastructure tasks, and social engineering. Expel also observed the actors using AI systems to audit their malicious coding assessments in an apparent attempt to make the backdoors harder for AI-based review to detect. According to Expel’s reporting, between January 1 and March 31, 2026, HexagonalRodent exfiltrated 26,584 cryptocurrency wallets from 2,726 infected developer systems and linked the activity to approximately or up to $12 million in crypto assets. Expel also linked the group to a supply-chain compromise involving the fast-draft VSCode extension used to distribute OtterCookie. Internal panels and workflow systems observed by Expel indicated a structured operation with 31 campaign IDs/operators across six teams.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DPRK-aligned group targeting Web3 developers through fake job offers and backdoored coding assessments, using AI-generated personas and AI tools to improve social engineering and sustain fraudulent remote engineering roles for source code, signing key, credential, and cryptocurrency theft.
Runs an active campaign targeting software developers, especially Web3 developers, through fake job interviews and malicious coding tests to steal cryptocurrency and NFTs. The group also conducted a supply chain attack via a compromised VSCode extension.
Cryptocurrency theft campaign targeting Web3 developers through fake LinkedIn job offers and malicious coding assessment tools that deploy credential-stealing malware.
Targets individual Web3 developers through fake job offers, fake company websites, and malicious coding assessments to deploy malware and steal cryptocurrency wallet data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.