Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster. In the observed campaign, attackers delivered malicious GitHub and GitLab repositories via fake job offers, code review requests, and technical testing lures. The repositories abused hidden .vscode/tasks.json files to trigger execution when opened in Visual Studio Code or Cursor; Cursor reportedly executed the task silently, while VS Code prompted for approval. On macOS and Linux, attackers deployed Go-based Overlord RAT binaries and used them to maintain persistent WebSocket command-and-control connectivity, including to 23.137.105[.]75:5173. The malware was cross-platform overall, with Windows using a separate JavaScript/Python infostealer chain rather than an Overlord binary. Proofpoint reported custom Overlord modules named browserlogin, companywallet, and cleanup. Observed capabilities associated with the Overlord-based macOS and Linux payloads included remote access, persistence via a malicious VSIX extension disguised as google-update-support.vsix, theft of browser credentials, browser wallet extension data, standalone cryptocurrency wallet directories, browser cookies, and anti-forensic cleanup. On macOS, a secondary binary named darwin-password-prompt displayed a fake system password dialog to capture the user password, after which the malware modified Keychain access controls and extracted secrets including Safe Storage keys from browsers such as Chrome, Brave, Edge, Opera, Vivaldi, Arc, Yandex, and Chromium. On Linux, the malware used Zenity to present a fake credential prompt and attempted to extract secrets from GNOME Keyring using secret-tool or Python D-Bus methods. Stolen data was compressed into ZIP archives and exfiltrated to attacker-controlled infrastructure, including 23.137.105[.]75:5173.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct threat actors attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The malware deployed through this campaign is cross-platform, capable of running on macOS, Linux, and Windows. It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.
On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attacker’s servers.
36 distinct techniques documented for this family, organized by ATT&CK tactic.
The hidden tasks.json file defines a task with runOptions.runOn: "folderOpen", a VS Code feature that executes the task automatically when the folder is opened in the editor.
On macOS and Linux, the script installs a malicious VS Code extension (VSIX) disguised as a Google service, then launches the Overlord backdoor. ... On Linux, the malware uses ... Python scripts.
The tasks.json file launches run-update-hidden-launch.vbs via wscript.exe //B (hidden window), which calls run-update.cmd.
The tasks.json file launches run-update-hidden-launch.vbs via wscript.exe //B (hidden window), which calls run-update.cmd.
Once Python is available, the credential stealer (detect_malware.py) is executed for each browser profile.
Unlike Linux/macOS, the Windows attack does not deploy a Go binary. It runs entirely as JavaScript inside the editor's Electron process using ELECTRON_RUN_AS_NODE=1...
When a developer clones the repository and opens it in Visual Studio Code or Cursor, a hidden file called tasks.json inside a concealed .vscode folder automatically runs malicious scripts.
The campaigns abused Visual Studio Code workflows and deployed a stealthy new technique using malicious Visual Studio Extensions (VSIX) that requires minimal user interaction.
The hidden tasks.json file defines a task with runOptions.runOn: "folderOpen", a VS Code feature that executes the task automatically when the folder is opened in the editor.
On macOS and Linux, the script installs a malicious VS Code extension (VSIX) disguised as a Google service...
The hidden tasks.json file defines a task with runOptions.runOn: "folderOpen", a VS Code feature that executes the task automatically when the folder is opened in the editor.
the malware leverages the password to extract browser credentials from Keychain and GNOME Keyring and subsequently relaunches itself as root to perform further Keychain and GNOME Keyring dumps.
Every time the user opens VS Code or Cursor on macOS or Linux, the VSIX extension activates, checks whether the subsequent infection portions are already running, and re-launches them if not.
The initial launcher (run-update.sh) is a bash script with an embedded Base64-encoded payload... The CMD file decodes an embedded script... The three encrypted payloads are decrypted at runtime using the hardcoded AES-256-GCM key...
...installs a malicious VS Code extension (VSIX) disguised as a Google service... The attackers used convincing fake company names and professional sender domains to make their outreach appear legitimate.
The infection chain finishes by deleting malicious payloads and directories from the cloned repository in an effort to clean up forensic artifacts, while maintaining persistence through the VSIX extension.
It also schedules cleanup of vendor/ and .vscode/ via a background subshell that survives editor shutdown.
The Linux backdoor uses Zenity... to create a prompt to collect user credentials. ... a second embedded Mach-O binary named darwin-password-prompt creates a fake system dialogue to prompt the user to enter their password.
On macOS, a secondary embedded binary called darwin-password-prompt presents a fake system dialog asking the user for their device password. ... On Linux, the malware uses a native system dialog tool called Zenity to create a similar fake prompt...
The Overlord RAT first extracts browser wallet extensions and standalone wallet directories and transmits them as a ZIP archive to the C2 server.
The Windows variant targets 35 cryptocurrency wallet extensions, 18 standalone wallet applications, and browser cookies. All collected data, including wallet contents, Safe Storage keys, login credentials, and browser cookies, is packaged into a ZIP file...
After the password is collected and validated, the malware modifies browser keychain access and dumps credentials from Chrome, Brave, Edge, Opera, and several other browsers. On Linux, ... targets GNOME Keyring credentials...
The Linux backdoor uses Zenity... to create a prompt to collect user credentials. ... a second embedded Mach-O binary named darwin-password-prompt creates a fake system dialogue to prompt the user to enter their password.
It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.
Organizations should also ... monitor outbound connections for unusual traffic to unknown WebSocket endpoints.
131 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cross-platform backdoor framework used to maintain persistent C2 connectivity on macOS, Linux, and Windows. In this campaign it enables remote access and supports follow-on credential theft, browser data exfiltration, and cryptocurrency wallet theft.
Cross-platform malware/C2 framework used in this campaign on Linux and macOS. It deploys Go-based RAT binaries, establishes persistent WebSocket C2, steals browser wallet extensions and wallet directories, prompts for the user’s system password, extracts credentials from Keychain and GNOME Keyring, and relaunches itself as root for additional credential dumping.
An open-source Go C2 framework repurposed by the threat actor as cross-platform malware. In this campaign it acts as a persistent RAT on Linux and macOS, communicating with a hardcoded C2 over WebSocket, performing remote command execution, system reconnaissance, credential theft, browser and crypto-wallet theft, exfiltration, persistence via malicious VSIX extensions, and cleanup of forensic artifacts. The actor added custom modules for browser credential theft, crypto wallet theft, and anti-forensics.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.