← Back to feed
TechJun 986% confidenceConfidence 86% — the share of independent, credible sources corroborating the core facts.

North Korean Hackers Launch New Phishing Campaign Targeting Developers with Fake Job Offers

Center 100%
2 sources

A newly identified North Korea-linked threat group called UNK_DeadDrop sent over 250 phishing emails to employees at nearly 100 organizations over six weeks, using fake job offers and code review requests to deliver malware. The campaign, tracked by Proofpoint, targets developers primarily in technology, finance, education, and business services, directing victims to malicious GitHub repositories that install cross-platform malware capable of stealing cryptocurrency wallets and browser credentials. Researchers say the shift from social-media-based fake interviews to large-scale email phishing suggests North Korean cyber operations are industrializing and scaling up.

Security researchers at Proofpoint have identified a previously unseen North Korea-aligned threat cluster, designated UNK_DeadDrop, which conducted a phishing campaign between April and May targeting developers at roughly 100 organizations, predominantly in the United States. Unlike the related Lazarus-linked Contagious Interview campaign, which used LinkedIn and staged fake interviews, UNK_DeadDrop relies on email to send unsolicited job offers or peer code-review requests, spoofing real companies including Ondo Finance, Empower Pharmacy, and NXLog. Victims are directed to attacker-controlled GitHub repositories disguised as coding assignments; opening these in an IDE silently triggers a platform-specific loader that installs a malicious VS Code extension masquerading as a Google service. On macOS and Linux, the malware deploys a Go-based remote access trojan built on the open-source Overlord C2 framework, with custom modules for stealing browser credentials, cryptocurrency wallet data, and keychain information, while also prompting users for their system password via a fake dialog. Windows systems run a parallel JavaScript-based attack inside the editor's Electron process, targeting 35 wallet extension IDs and credentials across Chromium and Firefox browsers. Proofpoint researchers noted the new self-contained payload and distinct infrastructure confirm UNK_DeadDrop is an independent cluster rather than a rebranding of Contagious Interview. The researchers concluded the campaign signals a maturation and industrialization of North Korea-aligned financial cybercrime operations.

What's missing

The report does not clarify how many victims, if any, were successfully compromised or what the total financial losses were; attribution confidence level (e.g., whether any government agency has formally corroborated the DPRK link) is also not addressed.

How coverage differed

Both outlets report the same core Proofpoint findings with neutral framing; The Register provides substantially more technical depth on malware mechanics and infrastructure, while TechRadar offers a broader contextual comparison to Lazarus Group campaigns for a general audience.

What different sources said

  • TechRadarCenter

    North Korean hackers are at it again — phishing scheme targets hundreds of workers to try and steal crypto and more

  • Norks blast 250+ fake job offers to developers over 6 weeks to try and snarf creds and crypto

Related

TechConfidence 69% — the share of independent, credible sources corroborating the core facts.

Samsung Galaxy S25 and S25 FE See Significant Price Cuts

Samsung's Galaxy S25 and Galaxy S25 FE smartphones are currently available at notably reduced prices, with the S25 FE dropping $201 (33%) to $449 on Woot for a limited time. The price reductions come amid a competitive smartphone market and ahead of anticipated future Samsung releases. The discounts make previously premium-priced devices more accessible to budget-conscious consumers.

2 sourcesJun 16
TechConfidence 100% — the share of independent, credible sources corroborating the core facts.

Anthropic Disables Fable 5 and Mythos 5 AI Models Globally After US Government Export Control Order

Anthropic has suspended all public access to its two most advanced AI models, Fable 5 and Mythos 5, after the US Commerce Department issued an export control directive ordering the company to block foreign nationals from accessing them on national security grounds. The order came just three days after Fable 5's public launch and reportedly stems from government concerns about a potential jailbreak that could enable the models to assist with cyberattacks, though Anthropic says it received only verbal evidence of a narrow, non-universal vulnerability. The shutdown affects all customers globally — including enterprise users and Anthropic employees — and marks a significant escalation of US efforts to restrict foreign access to advanced AI models themselves, rather than just the chips that power them.

4 sourcesJun 16
TechConfidence 89% — the share of independent, credible sources corroborating the core facts.

Xbox Free Play Days Offers Three Games Free to Play June 11–14

Microsoft's Xbox Free Play Days program is offering Hell Let Loose, State of Decay 2: Juggernaut Edition, and Blasphemous 2 at no cost from June 11 to June 14. Hell Let Loose requires an Xbox Game Pass Ultimate, Premium, or Essential membership, while State of Decay 2 and Blasphemous 2 (via a five-hour timed trial) are accessible to all Xbox console owners. Players who wish to keep any of the games can purchase them at a limited-time discount and retain any achievements earned during the free period.

2 sourcesJun 13