UNK_DeadDrop is a likely North Korea-aligned threat cluster focused on software developers, particularly individuals and organizations connected to cryptocurrency, finance, technology, education, and related business services. The activity was observed at scale in 2026 and is characterized by phishing campaigns that use fake job offers, coding assignments, code review requests, and technical testing lures to induce targets to clone attacker-controlled repositories and open them in developer environments such as Visual Studio Code and Cursor. The cluster’s tradecraft centers on abusing normal developer workflows rather than relying solely on conventional malware delivery. Malicious repositories are configured to trigger hidden task automation when opened in the editor, resulting in execution of platform-specific payloads on macOS, Linux, and Windows. On macOS and Linux, the operation has used modified variants of the open-source Overlord command-and-control framework to establish persistent remote access and conduct credential theft and wallet theft. On Windows, the activity has used an editor-resident infostealer chain designed to execute within the development environment and exfiltrate data without necessarily maintaining persistence. UNK_DeadDrop has demonstrated strong interest in stealing cryptocurrency assets and authentication material. Reported collection objectives include browser credentials, cookies, browser wallet extension data, standalone wallet application data, and secrets stored in operating-system credential stores such as Keychain and GNOME Keyring. The malware has also used deceptive password prompts to harvest local system credentials and then leverage those credentials to access protected browser or keyring material. On Windows, the tooling has been reported to target numerous cryptocurrency wallet extensions and applications and to extract browser data through native credential access mechanisms and browser-protection bypass techniques. Persistence and stealth are notable aspects of the cluster’s tooling. The operation has used a malicious VS Code extension to relaunch malware when supported editors are opened on macOS and Linux, while also incorporating cleanup behavior and iterative tooling changes. The use of legitimate developer platforms and trusted workflows increases the likelihood of execution and reduces suspicion, especially among technically proficient targets. UNK_DeadDrop shows meaningful overlap with the DPRK-linked Contagious Interview activity cluster in victimology, social engineering themes, and the theft of cryptocurrency wallets and credentials. However, it has also been tracked as a distinct cluster due to differences in delivery method, infrastructure, payload design, and telemetry. In particular, UNK_DeadDrop has been associated with email-based initial access and abuse of editor task automation, whereas Contagious Interview has been more widely associated with other recruitment-channel approaches and different malware families. Based on targeting, tradecraft, and operational objectives, UNK_DeadDrop is best understood as part of the broader North Korean ecosystem targeting developers and cryptocurrency-related assets.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
40 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
124 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Abused developer platforms and tools to steal credentials and cryptocurrency wallets from developers.
A North Korea-aligned activity cluster targeting developers with phishing emails that impersonate recruiters or code reviewers and direct victims to malicious GitHub/GitLab repositories. The campaign abuses hidden VS Code task automation to execute malware, establish persistence, steal credentials, exfiltrate browser data, and drain cryptocurrency wallets across macOS, Linux, and Windows.
Targets developers with fake job offers and coding assignments delivered by email, leading to deployment of cross-platform malware for cryptocurrency wallet theft and credential theft.
Credential- and cryptocurrency-theft phishing campaign targeting developers through recruitment and code-review lures, using malicious GitHub repositories and cross-platform malware across macOS, Linux, and Windows.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.