Skip to main content
Mallory
🇰🇵 KP3 malware families

HexagonalRodent

Also known ashexagonalrodent

HexagonalRodent is a financially motivated, state-sponsored North Korean threat group tracked by Expel as Expel-TA-0001. Expel assesses it as a subgroup or operational offshoot overlapping with CrowdStrike’s Famous Chollima; other vendors track overlapping activity as Contagious Interview. The reporting also describes the group as widely believed to sit within the broader Lazarus ecosystem. The group primarily targets Web3 and DeFi developers, as well as software developers more broadly, with the objective of stealing cryptocurrency and NFTs. Its operations rely heavily on employment-themed social engineering: fake recruiter outreach on LinkedIn and other career platforms, fraudulent job postings, fake company websites, and fabricated employee or leadership personas. Expel reported that the group used generative AI tools including ChatGPT, Cursor, and Anima to support malware development, infrastructure tasks, social engineering, and creation of fake companies and LinkedIn presences; in one reported case, a front company was formally incorporated in Mexico. HexagonalRodent commonly delivers malware through malicious coding assessments sent to job applicants. The infection chain abuses VSCode tasks.json with runOn:"folderOpen" to trigger execution when a project folder is opened, and also embeds backdoored code that executes when the project is run, providing a secondary path for victims not using VSCode or with automated tasks disabled. Malware associated with the group includes BeaverTail, OtterCookie, and InvisibleFerret. BeaverTail is used for credential theft, including from browser password managers, macOS Keychain, Linux Keyring, and 1Password; OtterCookie and InvisibleFerret provide reverse-shell or ongoing access. The malware is described as written in NodeJS and Python and uses obfuscated JavaScript to blend into developer environments and complicate detection. Expel reported that between January and March 2026 the campaign compromised 2,726 developer systems and exfiltrated 26,584 cryptocurrency wallets, with wallets holding up to approximately $12 million in crypto assets. Reporting also linked at least 13 victim wallets to a known DPRK-operated Ethereum address. Expel’s investigation uncovered internal command-and-control and workflow systems indicating a structured operation with 31 operators across six teams. In early 2026, the group was also linked to a supply-chain compromise of the fast-draft VSCode extension used to distribute OtterCookie.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Financial Services
  • Software & Services

Where they're from

Attributed origin per open-source reporting.

  • KP
MITRE ATT&CK

Tradecraft

18 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

12 of 15 tactics22 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0043
Reconnaissance
1 technique
T1598
Phishing for Information
TA0001
Initial Access
3 techniques
T1195×2
Supply Chain Compromise
T1199×2
Trusted Relationship
T1566
Phishing
T1566.003×5
Spearphishing via Service
TA0002
Execution
2 techniques
T1059×2
Command and Scripting Interpreter
T1204×2
User Execution
T1204.002×4
Malicious File
TA0003
Persistence
1 technique
T1546
Event Triggered Execution
TA0004
Privilege Escalation
1 technique
T1546
Event Triggered Execution
TA0005
Stealth
2 techniques
T1027×2
Obfuscated Files or Information
T1036×2
Masquerading
TA0006
Credential Access
2 techniques
T1056
Input Capture
T1056.001
Keylogging
T1555×2
Credentials from Password Stores
TA0007
Discovery
1 technique
T1083
File and Directory Discovery
TA0008
Lateral Movement
1 technique
T1021
Remote Services
TA0009
Collection
1 technique
T1056
Input Capture
T1056.001
Keylogging
TA0011
Command and Control
1 technique
T1071
Application Layer Protocol
T1071.001
Web Protocols
TA0010
Exfiltration
1 technique
T1041×3
Exfiltration Over C2 Channel
IOCS

Observables

2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping18

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal3

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables2

Domains, IPs, and hashes tied to this actor, refreshed continuously.

HexagonalRodent | Mallory