A North Korea-aligned campaign tracked as DeceptiveDevelopment has used fake recruiter personas and trojanized coding challenges on GitHub, GitLab, and Bitbucket to compromise freelance software developers. Active since at least November 2023, the operation has particularly targeted developers working on cryptocurrency and decentralized-finance projects, with hundreds of victims identified globally across Windows, Linux, and macOS.
Victims who run the malicious challenge receive the BeaverTail infostealer and downloader, followed by the Python-based InvisibleFerret backdoor. The malware steals cryptocurrency wallets, browser credentials, password-manager data, and other sensitive information; newer versions add Telegram exfiltration, selective clipboard theft, and keylogging, and can deploy AnyDesk for persistent remote access. The activity is linked to North Korean IT-worker and recruiter impersonation operations and overlaps with tactics associated with the Famous Chollima ecosystem and related DPRK campaigns.

Pull IOCs and campaign context straight into your stack.
7 events from the most recent confirmed update back to the earliest known activity.
On May 26, 2026, a fraudulent developer job poster targeted Elastic Security Labs' community Slack workspace and sent interested developers trojanized e-commerce coding-challenge repositories. Elastic tracked the activity as REF9403, a DPRK-aligned Contagious Interview campaign using SVG-embedded JavaScript payloads assessed as OTTERCOOKIE-aligned to steal browser credentials, cryptocurrency wallets, files, and clipboard data and provide Socket.IO remote access.
In December 2024, ESET observed an InvisibleFerret version containing a separate mlip module for clipboard stealing and keylogging, limited to chrome.exe and brave.exe.
ESET first observed the DeceptiveDevelopment campaign in early 2024. The activity targeted freelance developers, particularly those involved in cryptocurrency and decentralized-finance projects.
ESET assessed that the North Korea-aligned DeceptiveDevelopment campaign had been active since at least November 2023, using fake recruiter personas and trojanized coding challenges against freelance developers.
Mandiant observed a DPRK threat actor send an engineer a fake LinkedIn job opportunity and a ZIP archive posing as a Python coding challenge. The archive delivered COVERTCATCH, which downloaded second-stage malware and persisted on the victim's macOS system through Launch Agents and Launch Daemons.
DPRK-affiliated actors used a fake Python job-interview challenge, RookeryCapital_PythonTest.zip, containing a PasswordManager application with a trojanized Pyperclip dependency. The embedded payload contacted akamaitechnologies[.]online and could Base64-decode and execute attacker-supplied Python code, providing remote command execution.
A threat actor used a malicious pybitjs PyPI package and fake coding-assignment repository to compromise a monitored decoy developer environment, deploying WinosStager and information-stealing payloads. The operators later returned as SYSTEM, installed clipboard- and screenshot-stealing tooling, established redundant persistence, and exfiltrated host data; the activity was assessed as consistent with PolinRider and the North Korea-linked Contagious Interview operation.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 55 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
8 references tracked. Mallory keeps watching after this page renders.
blog.deception.pro
Open sourceelastic.co
Open sourcehackingbutlegal.com
Open sourcecrowdstrike.com
Open sourcewelivesecurity.com
Open sourceelastic.co
Open sourcecloud.google.com
Open sourcereversinglabs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.