A recent analysis from Proofpoint revealed that North Korean hackers, identified as UNK_DeadDrop, are using phishing tactics to target software developers at nearly 100 organizations in the U.S. This campaign involves over 250 emails sent in early 2026, posing as job offers and code review requests, mainly focusing on cryptocurrency companies. The emails link to fake GitHub or GitLab repositories containing malicious scripts that covertly install malware to steal cryptocurrency and credentials.
Affected platforms include macOS, Linux, and Windows, each with tailored methods to access sensitive information, including browser data and cryptocurrency wallets. The operation exhibits similarities to previous North Korean campaigns targeting developers but remains tracked as a unique threat cluster.