DevPopper
Medium ConfidenceHigh ThreatDEV#POPPER • Famous Chollima
DevPopper is a North Korean threat campaign targeting software developers through fake job interviews and malicious npm packages. The operation involves creating fake companies and job postings to lure developers into downloading malware-laden coding tests or development tools. This campaign represents North Korea's evolving tactics to target the cryptocurrency and technology sectors through supply chain and social engineering attacks.
DevPopper is a North Korean threat campaign targeting software developers through fake job interviews and malicious npm packages. The operation involves creating fake companies and job postings to lure developers into downloading malware-laden coding tests or development tools. This campaign represents North Korea's evolving tactics to target the cryptocurrency and technology sectors through supply chain and social engineering attacks.
Target Sectors
Target Regions
Attributed to RGB (Reconnaissance General Bureau) (North Korea). Attribution confidence: Medium.
Future Outlook
DevPopper is expected to continue operations targeting Technology sectors.
First observed activity of DevPopper
Continued active operations