AkdoorTea is a Windows remote-access payload/backdoor observed in the North Korea-linked DeceptiveDevelopment (also referred to in reporting on Contagious Interview) campaign targeting software developers, particularly those involved in cryptocurrency and Web3. ESET reported it as a newly observed RAT delivered through fake recruiter and interview lures used by DeceptiveDevelopment, a cluster active since at least 2023 and assessed as distinct from Operation Dream Job but linked to the broader Lazarus umbrella through tooling overlap.
AkdoorTea was delivered via a Windows batch script, including ClickFix-1.bat, that downloaded an archive named nvidiaRelease.zip. That archive reportedly mixed legitimate Nvidia components with a trojanized Node.js installer and an obfuscated BeaverTail script, then launched BeaverTail and AkdoorTea. The broader campaign used staged pre-interviews, fake video-assessment sites, ClickFix-style instructions that tricked victims into running terminal commands, and trojanized coding challenges hosted in repositories. The campaign targeted Windows, macOS, and Linux overall, but AkdoorTea itself is specifically described as a Windows payload.
Within the DeceptiveDevelopment intrusion chain, first-stage malware such as BeaverTail or OtterCookie was used to steal browser credentials and cryptocurrency wallet data and fetch second-stage payloads. AkdoorTea was one of the more advanced Windows payloads added to this arsenal, alongside other malware families such as InvisibleFerret, Tropidoor, TsunamiKit, GolangGhost/WeaselStore, and PylangGhost. Reporting states the AkdoorTea activity used new command-and-control infrastructure.
ESET and related reporting state AkdoorTea is similar to Akdoor and shares commonalities with Akdoor, which is described as a variant of the NukeSped/Manuscrypt implant. This similarity was cited as reinforcing links to the Lazarus Group umbrella or suggesting malware sharing/reuse across North Korean clusters. High-confidence associated artifacts and identifiers mentioned in the reporting include nvidiaRelease.zip, ClickFix-1.bat, and drvUpdate.exe, the TCP RAT sample to which the AkdoorTea codename was assigned.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
3 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
"Researchers also observed a new Windows remote-access payload they dub 'AkdoorTea'..."
"The latest addition to the threat actor's arsenal is a remote access trojan dubbed AkdoorTea..."
North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers
9 distinct techniques documented for this family, organized by ATT&CK tactic.
"...AkdoorTea that's delivered by means of a Windows batch script. The script downloads a ZIP file... and executes a Visual Basic Script..."
"...executes a Visual Basic Script present in it, which then proceeds to launch BeaverTail and AkdoorTea payloads..."
4 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool referenced in DPRK-linked DeceptiveDevelopment reporting.
Previously undocumented backdoor used in a DPRK-linked campaign targeting cryptocurrency/software developers; mentioned alongside TsunamiKit and Tropidoor.
New Windows remote-access payload delivered via an archive (nvidiaRelease.zip) fetched by a ClickFix batch script; bundled with trojanized Node.js installer and obfuscated BeaverTail plus new C2 infrastructure.
New Windows remote-access payload delivered via an archive (nvidiaRelease.zip) fetched by a ClickFix batch script; bundled with trojanized Node.js installer and obfuscated BeaverTail plus new C2 infrastructure.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.