Proofpoint reports that hacker activities related to North Korea are developing phishing attacks themed around recruitment, code reviews, and more, targeting nearly 100 organizations in sectors including finance, crypto, education, and technology. Attackers use emails to lure victims into cloning malicious GitHub repositories and opening the project in VS Code or Cursor, triggering cross-platform malicious code execution. Proofpoint has named the campaign UNK_DeadDrop, saying it uses VS Code project “folderOpen auto-execution” technology and installs malicious extensions disguised as Google services to steal data such as browser wallet extensions, desktop wallets, and credentials. (The Hacker News)

View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pinned