Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Collapse
Brand Logo
UDS UDS: $1.604
24h: 0.51%
Trade UDS
Gate.io
Gate.io
UDS / USDT
KuCoin
KuCoin
UDS / USDT
MEXC
MEXC
UDS / USDT
BingX
BingX
UDS / USDT
BitMart
BitMart
UDS / USDT
LBank
LBank
UDS / USDT
XT.COM
XT.COM
UDS / USDT
Uniswap v3
Uniswap v3
UDS / USDT
Biconomy.com
Biconomy.com
UDS / USDT
WEEX
WEEX
UDS / USDT
PancakeSwap v3
PancakeSwap v3
UDS / USDT
Pionex
Pionex
UDS / USDT
COINSTORE
COINSTORE
UDS / USDT
Sushiswap v3
Sushiswap v3
UDS / USDT
Picol
Picol
UDS / USDT

Earn up to 50 UDS per post

Post in Forum to earn rewards!

Learn more
UDS Right

Spin your Wheel of Fortune!

Earn or purchase spins to test your luck. Spin the Wheel of Fortune and win amazing prizes!

Spin now
Wheel of Fortune
selector
wheel
Spin

Paired Staking

Stake $UDS
APR icon Earn up to 50% APR
NFT icon Boost earnings with NFTs
Earn icon Play, HODL & earn more
Stake $UDS
Stake $UDS
UDS Left

Buy UDS!

Buy UDS with popular exchanges! Make purchases and claim rewards!

Buy UDS
UDS Right

INFLUENCER LEVEL

Based on the number of subscribers

MULTIPLIER

up to 10k

x1.1

10-25k

x1.25

25-100k

x1.5

100k-250k

x2

250k-1m

x3

1m+

x5

Post links to Undeads Forum messages or Undeads products to receive additional rewards

Post limits and staking coefficients applied similar to Forum posts

Discord, Telegram, Twiter

Post in Forum to earn rewards!

UDS Rewards
  1. Home
  2. Freelancing/Online work exchange
  3. North Korean Hackers Are Targeting Freelance Developers With Fake Job Offers to Steal Crypto

North Korean Hackers Are Targeting Freelance Developers With Fake Job Offers to Steal Crypto

Scheduled Pinned Locked Moved Freelancing/Online work exchange
2 Posts 2 Posters 6 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
This topic has been deleted. Only users with topic management privileges can see it.
  • nihalsariN Offline
    nihalsariN Offline
    nihalsari
    wrote last edited by
    #1

    983c67ca-1d4b-4d99-b194-c3eb4911f7eb-image.png

    A sophisticated malware campaign attributed to Nickel Alley, a threat group operating on behalf of the North Korean government, is targeting software developers on freelance platforms including Upwork and Fiverr with fake high-paying job opportunities designed to deliver crypto-stealing malware. Researchers at the Sophos Counter Threat Unit have documented the campaign's methodology in detail: the group creates fake LinkedIn company pages and coordinating GitHub accounts to build credibility, advertises tech talent and managed service solutions through generic-looking websites, and lures developers through a fabricated interview process that eventually persuades victims to download and execute malicious code. The attacks use typosquatting or compromised legitimate npm repositories, with victims instructed to run npm install and npm start commands that initiate malware delivery rather than a genuine development task.

    The malware payloads used by Nickel Alley have evolved over time. The group has deployed PyLangGhost RAT through a ClickFix tactic where a fake web interface presents an error message instructing the victim to run a command locally to fix it, a command that instead triggers a chain of actions installing the remote access trojan. A GoLang-based variant called GoLangGhost RAT was used in earlier campaigns. The primary goal appears to be cryptocurrency theft, but Sophos notes the group has explicitly planned to use initial access for supply chain compromise and corporate espionage as secondary objectives. Developers in finance and technology are at elevated risk given Nickel Alley's targeting profile, and Sophos recommends that organizations monitor command execution and network traffic spawning from Node.js processes as an indicator of compromise.

    1 Reply Last reply
    0
    • lingriidddL Offline
      lingriidddL Offline
      lingriiddd
      wrote last edited by
      #2

      North Korean hackers are on Upwork offering fake dev jobs, so if the interview feels too good to be true it is because it ends with npm install malware dot js.

      1 Reply Last reply
      0


      • Login or register to search.
      Powered by NodeBB Contributors
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups