Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligencegovernment-diplomatic-threatcredential-stealer-activity

North Korea-linked Social Engineering Campaigns Targeting Developers and Defense Supply Chains

Updated 3mo agoFirst seen Jan 26, 20264 sources

North Korea–aligned operators, including Lazarus (aka HIDDEN COBRA), are running multiple social-engineering-led intrusion campaigns aimed at stealing sensitive technology and establishing durable access. Reporting on Operation DreamJob describes fake job-offer lures used to compromise European drone manufacturers and defense contractors, with tooling and infrastructure designed to evade traditional defenses and support cyber-espionage against UAV-related intellectual property. Separately, a developer-focused operation dubbed “Fake Font” uses fake recruiter outreach and malicious GitHub repositories to trick engineers into opening projects that abuse Visual Studio Code automation (via .vscode/tasks.json) and disguised payloads (e.g., .woff2 “font” files) to execute multi-stage malware that ultimately deploys the InvisibleFerret Python backdoor for credential and crypto-wallet theft and long-term access.

A distinct DPRK-linked campaign reported by Darktrace targets South Korean users with spear-phishing that delivers a JSE script masquerading as an HWPX document and then abuses VS Code tunnels as a covert C2 channel over trusted Microsoft infrastructure, complicating detection in developer-heavy environments. Other items in the set describe unrelated activity: phishing abuse of Vercel to deliver remote-access tooling, exploitation of CVE-2025-51683 (blind SQLi) in the Mjobtime time-tracking app to reach MSSQL xp_cmdshell, a hospitality-focused DCRat campaign using ClickFix and MSBuild.exe, a generic CSS exfiltration technique write-up, and Trend Micro research on the PeckBirdy LOLBins framework used by China-aligned intrusion sets—none of which are part of the DPRK developer/defense recruitment-themed operations above.

Share:
North Korea-linked Social Engineering Campaigns Targeting Developers and Defense Supply Chains
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 26, 20265mo ago

Darktrace identifies VS Code tunnel espionage targeting South Koreans

Darktrace reported a DPRK-linked cyberespionage campaign targeting South Korean users with spear-phishing emails delivering a JSE file disguised as an HWPX document. After execution, the malware established a Visual Studio Code tunnel through Microsoft infrastructure and used a compromised legitimate website to broker remote access.

Oct 18, 20258mo ago

DPRK 'Fake Font' developer campaign begins

Lazarus Group launched a developer-focused campaign dubbed 'Fake Font' more than 100 days before late January 2026, using fake LinkedIn recruiters and malicious GitHub coding assessments. The repositories abused Visual Studio Code task automation and disguised JavaScript malware as .woff2 font files to deploy the InvisibleFerret backdoor.

Mar 25, 20251y ago

Operation DreamJob targets European drone and defense firms

In late March 2025, Lazarus Group began a renewed Operation DreamJob cyberespionage campaign against European drone manufacturers and defense contractors, using fake job offers and trojanized documents to steal UAV-related intellectual property. Researchers later confirmed at least three targeted companies in Central and Southeastern Europe.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
2 linked
Malware
1 linked
Affected products
8 linked
Visual Studio CodeHangul Word ProcessorReactGithubZoomLinkedinGithubChrome
Organizations
7 linked
Microsoft CorporationHancomLinkedinDarktraceGitHubOpenSourceMalwareYespp
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.