New malware DEV#POPPERtargets software developers on Windows, Linux and macOS systems.

This campaign is associated with North Korea and has been detected targeting victims in South Korea, North America, Europe, and the Middle East.
“This form of attack is a sophisticated form of social engineering, designed to manipulate individuals into revealing confidential information or taking actions they would normally avoid,” said Securonix researchers Den Iuzvyk and Tim Peck in a new report published in The Hacker News.
See more: Hackers target Python developers with fake “Crytic-Compilers” package on PyPI
DEV#POPPER is the name given to an active malware campaign that tricks software developers into downloading malware hosted on GitHub under the guise of a job interview. This campaign also shares common modus operandi with Contagious Interview, which is monitored by Palo Alto Networks Unit 42.
Indications that the campaign was broader in scope and spans multiple platforms emerged this month, when researchers discovered techniques targeting both Windows and macOS, delivering an updated version of a malware called BeaverTail.
Securonix's document on the attack chain confirms that threat actors pose as interviewers for developer positions, urging candidates to download a ZIP file for a coding assignment.
Included with the file is an npm module that, once installed, triggers the execution of a malicious JavaScript (i.e., BeaverTail), which identifies the operating system it is running on and establishes a connection to a remote server to extract data of interest.
Additionally, BeaverTail has the ability to download next-stage payloads, including a Python gateway called InvisibleFerret. This gateway is designed to collect detailed system metadata, access cookies stored in browsers, execute commands, upload/download files, and capture keystrokes and clipboard content.
New features added to recent samples include the use of improved obfuscation, AnyDesk remote monitoring and management (RMM) software for persistence, as well as improvements to the FTP mechanism used for data export.
Also read: Python and PHP scripts are executed without warning due to a bug in WhatsApp
Additionally, the Python script acts as a conduit for executing a helper script, responsible for stealing sensitive information from various web browsers, such as Google Chrome, Opera, and Brave, on different operating systems.
"This evolved version of the original DEV#POPPER campaign leverages Python scripts to execute a complex, multi-faceted attack aimed at extracting sensitive information from victims, now offering much more powerful capabilities," the researchers said.
Recorded Future revealed that North Koreans continue to use foreign technology – such as devices from Apple, Samsung, Huawei and Xiaomi, as well as various social media platforms such as Facebook, X, Instagram, WeChat, LINE and QQ – to access the internet, despite the strict sanctions imposed on them.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Another significant change in internet user behavior is the use of virtual private networks (VPNs) and proxies to circumvent censorship and surveillance, as well as the use of McAfee antivirus software. This suggests that the country is not as isolated as it seems.

See also: Chinese hackers target Japanese companies with LODEINFO and NOOPDOOR Malware
“Despite sanctions, North Korea continues to import foreign technology, often through trade relations with China and Russia,” the company says. “This suggests a shift toward greater security awareness asusers seek to avoid detection by the regime.”
Source: thehackernews
