www.infosecurity-magazine.com 6/8/2026, 3:20:44 PM · external

North Korean hackers hit developers via fake GitHub repo phishing

North Korean hackers hit developers via fake GitHub repo phishing
Developing story incident 2 articles tracked
North Korean UNK_DeadDrop phishing campaign targets developers
CyberSIXT Evidence Panel
Primary Source proofpoint.com
Threat Actor
UNK_DeadDrop

A recent analysis from Proofpoint revealed that North Korean hackers, identified as UNK_DeadDrop, are using phishing tactics to target software developers at nearly 100 organizations in the U.S. This campaign involves over 250 emails sent in early 2026, posing as job offers and code review requests, mainly focusing on cryptocurrency companies. The emails link to fake GitHub or GitLab repositories containing malicious scripts that covertly install malware to steal cryptocurrency and credentials.

Affected platforms include macOS, Linux, and Windows, each with tailored methods to access sensitive information, including browser data and cryptocurrency wallets. The operation exhibits similarities to previous North Korean campaigns targeting developers but remains tracked as a unique threat cluster.

View Primary Source Via www.infosecurity-magazine.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline