BigSquatRat is a North Korea-linked threat activity cluster focused on compromising cryptocurrency and trading-bot developers through malicious GitHub repositories and npm package lifecycle execution. The operation uses developer-themed lures, especially repositories advertising crypto trading bots and related tooling, to induce victims to install packages that execute a malicious post-install script. The resulting implant, commonly referred to as MicrosoftSystem64, is a cross-platform Node.js backdoor designed for persistence, remote tasking, credential and wallet theft, and broad post-compromise collection. The malware establishes user-level persistence across Windows, Linux, and macOS and is built to survive beyond the lifetime of the original lure repository, indicating a separation between lure infrastructure and active victim management. Observed functionality includes command execution, file read and write operations, directory listing, system reconnaissance, screenshot capture, clipboard access, SSH material collection, wallet discovery, binary deployment, and agent removal. The implant also includes keylogging and sensitivity-aware input capture logic intended to prioritize credentials and wallet-related data. Collection priorities include shell histories, cloud and developer credentials, container and orchestration configuration, source-development secrets, SSH keys, Telegram Desktop data, and cryptocurrency wallet artifacts. Operationally, the campaign has used multiple GitHub accounts and both active and archived lure repositories, with evidence that repository retirement does not terminate infections on already compromised hosts. Recovered strings indicate WebSocket-based command-and-control and exfiltration mechanisms associated with Hugging Face services. The actor demonstrates persistence, defense evasion through obfuscation and detached execution, and extensive post-exploitation aimed at harvesting high-value developer and crypto-related access. BigSquatRat is assessed as financially motivated, with targeting centered on individuals and environments likely to hold cryptocurrency assets, wallet data, exchange access, and developer secrets that can enable direct theft or follow-on compromise.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.