Breaking
April 23, 2025

North Korean hackers are using LinkedIn to entice developers to coding challenges – here’s what you need to know | usagoldmines.com


  • Slow Pisces targets crypto developers with bad code disguised as stock analysis tools
  • Malicious code hides in plain sight, using GitHub projects and YAML deserialization tricks
  • Victims unknowingly install RN Loader and RN Stealer through rigged Python repositories

A hacker group from North Korea known as Slow Pisces has launched a sophisticated campaign targeting developers in the cryptocurrency sector through LinkedIn.

The group, also known as TraderTraitor or Jade Sleet, poses as recruiters to lure victims with seemingly genuine job offers and coding challenges, only to infect their systems with malicious Python and JavaScript code.

Thanks to this campaign, the group has been able to steal substantial amounts of cryptocurrency. In 2023 alone, they were linked to over $1 billion in stolen funds. A $1.5 billion hack at a Dubai exchange and a $308 million theft from a Japanese company are among the recent attacks.

Coders beware!

After initially sending PDF documents containing job descriptions, the malicious actors follow up with coding assignments hosted on GitHub.

Although these repositories appear to be based on legitimate open-source projects, they have been secretly altered to include hidden malware.

Victims, believing they are completing programming tests, unintentionally allow malware like RN Loader and RN Stealer onto their systems.

These booby-trapped projects mimic legitimate developer tools and applications. For instance, Python repositories might seem to analyze stock market trends using data from reputable sources, while secretly communicating with attacker-controlled domains.

The malware evades most detection tools by using YAML deserialization, avoiding commonly flagged functions like eval or exec. Once triggered, the loader fetches and executes additional payloads directly in memory, making it difficult to detect or remove.

One such payload, RN Stealer, is specifically designed to exfiltrate credentials, cloud configuration files, and stored SSH keys, particularly from macOS systems.

JavaScript variants of the malware operate similarly, using the Embedded JavaScript templating engine to hide malicious code, which activates only for targeted victims based on factors like IP addresses or browser headers.

Forensic analysis shows that the malware stores code in hidden directories and communicates over HTTPS using custom tokens. However, investigators were unable to recover the full JavaScript payload.

GitHub and LinkedIn have responded by removing the malicious accounts and repositories involved.

“GitHub and LinkedIn removed these malicious accounts for violating our respective terms of service. Across our products, we use automated technology, combined with teams of investigation experts and member reporting, to combat bad actors and enforce terms of service. We continue to evolve and improve our processes and encourage our customers and members to report any suspicious activity,” the companies said in a joint statement.

There is a growing need for caution when approached with remote job offers and coding tests. Developers are advised to use strong antivirus software and run unfamiliar code in secure environments, particularly when working in sensitive sectors like cryptocurrency.

Those concerned about security should verify they are using the best IDEs, which typically include integrated security features. Staying alert, and working on a secure, controlled setup, can significantly reduce the risk of falling prey to state-backed cyber threats.

Via Unit42

You may also like

​ 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

Shopify is hiring ChatGPT as your personal shopper, according to a new report erichs211@gmail.com (E...

Best Thunderbolt docks 2025: Extend your laptop’s capabilities | usagoldmines.com

This e-ink portable monitor handles 60Hz video and won’t bankrupt you | usagoldmines.com

Sandisk Extreme Pro SSD with USB4 review: Good performance, when it connects at full speed | usagol...

T-Mobile Adds New Plans With More Hotspot Data Juli Clover | usagoldmines.com

Instagram Launches 'Edits' App to Replace CapCut Juli Clover | usagoldmines.com

This cheating app teaches all the wrong lessons about AI – but some of you still might use it lance....

Sandisk Extreme Pro SSD with USB4 review: Style and good performance — when it connects at full spee...

Google Fi Gains New $35/Month Unlimited Plan, Improved iPhone Integration Juli Clover | usagoldmines...

Apple removed 'Available Now' from the Apple Intelligence webpage, but it may not have been Apple's ...

Glass bottles in, sand out – Disney World is crushing glass to make pathways and more in its latest ...

Universities (finally) band together, fight “unprecedented government overreach” Nate Anderson | usa...

Max starts charging extra to share your streaming account | usagoldmines.com

Harper Is an Offline Alternative to Grammarly for Obsidian Justin Pot | usagoldmines.com

ChatGPT head tells court OpenAI is interested in buying Chrome Ryan Whitwam | usagoldmines.com

Drunk man walks into climate change, burns the bottoms of his feet off Beth Mole | usagoldmines.com

Reolink security cams gain ‘Works With Home Assistant’ certification | usagoldmines.com

My Favorite Amazon Deal of the Day: These Anker Soundcore P20i Earbuds Daniel Oropeza | usagoldmines...

YouTube Will Soon Support Automatic Picture-in-Picture When Switching Tabs in Chrome Jake Peterson |...

These Refurbished Sonos Soundbars, Subwoofers, and Headphones Are on Sale for Earth Day Daniel Orope...

Google Messages update finally adds an important safety tool – and teases a feature I'm surprised th...

Best Windows backup software 2025: Protect your data! | usagoldmines.com

Instagram Launches New ‘Edits’ Video Editing App Tim | usagoldmines.com

1 in 2 Surveyed Willing to Pay at Least $10/Month for Apple Intelligence Joe Rossignol | usagoldmine...

OpenAI Wants to Buy Google's Chrome Browser Juli Clover | usagoldmines.com

Millions at risk as cybercriminals successfully compromise popular YouTube accounts: here's how to s...

Palantir to develop “ImmigrationOS” for ICE to speed up deportations | usagoldmines.com

Google won’t ditch third-party cookies in Chrome after all Ryan Whitwam | usagoldmines.com

Teamgroup MP44Q NVMe SSD review: Host Memory Bus champ — with a caveat | usagoldmines.com

Samsung is Doubling Your Galaxy S25 or Galaxy S25 Ultra Storage for Free Kellen | usagoldmines.com

Notion Mail Takes You Back to When Gmail Was Good Khamosh Pathak | usagoldmines.com

Whoop’s Strength Trainer Has Its Flaws, but Is Still Better Than Anything Its Competitors Have Beth ...

Siri Management Team Gets Overhaul After Apple Intelligence Failure Juli Clover | usagoldmines.com

What to Expect From the AirTag 2 Joe Rossignol | usagoldmines.com

Chinese tech companies want to enter the US market despite trade and tariff war | usagoldmines.com

Harvard sues to block government funding cuts John Timmer | usagoldmines.com

Taxes and fees not included: T-Mobile’s latest price lock is nearly meaningless Jon Brodkin | usagol...

73&Sunny GripStand review: The remote-control case you didn’t know you needed | usagoldmines.co...

The Most Common Reasons for Homebuyer's Remorse (and How to Avoid Them) Jeff Somers | usagoldmines.c...

You Can Now Make Google Messages Blur NSFW Images Emily Long | usagoldmines.com

Woot's New Apple Watch Solo/Braided Loop Sale Offers Up to Two Free Bands When You Buy One Mitchel B...

ChatGPT crosses a new AI threshold by beating the Turing test erichs211@gmail.com (Eric Hal Schwartz...

Man buys racetrack, ends up launching the Netflix of grassroots motorsports Scharon Harding | usagol...

Best SSDs: From SATA to PCIe 5.0, from budget to premium | usagoldmines.com

Can you really recover deleted files from a storage drive? Well… | usagoldmines.com

I won’t buy a wireless PC headset if it lacks this humble feature | usagoldmines.com

ChatGPT users annoyed by the AI’s incessantly ‘phony’ positivity | usagoldmines.com

Philips Hue leak hints at a Matter mystery | usagoldmines.com

Intel is giving Core Ultra 200S PCs a free performance boost | usagoldmines.com

Google Fi Introduces New Essentials Plan, Adds Upgrades to Unlimited Plans Kellen | usagoldmines.com

Gmail Gets New ‘Manage Subscriptions’ Tab on Android Tim | usagoldmines.com

Instagram Just Launched Its Version of CapCut Jake Peterson | usagoldmines.com

iPhone 14 vs. iPhone 16e Buyer's Guide: Should You Upgrade? Hartley Charlton | usagoldmines.com

Apple Releases New iOS 18.5 and macOS Sequoia 15.5 Public Betas Juli Clover | usagoldmines.com

iPhone 17 Air's Extreme Thinness Demoed in New Video Juli Clover | usagoldmines.com

I can't wait to try Edits, Instagram's answer to CapCut, and it's out now as a free download jacob.k...

'Ruined my entire week, month, and year': The Last of Us season 2's new episode has devastated viewe...

The second pair of open earbuds with Bose tech are coming, but not from Bose | usagoldmines.com

Hackers are hitting firewalls and VPNs to breach businesses | usagoldmines.com

12-year-old Doom 2 challenge map finally beaten after six-hour, 23K-demon grind Kyle Orland | usagol...

5 ways I lower my PC RAM usage to boost game performance | usagoldmines.com

Get this budget-friendly HP laptop with 16GB RAM for under $400 | usagoldmines.com

Today’s best laptop deals: Save big on work, school, home use, and gaming | usagoldmines.com

Galaxy S24 Enters Renewed Program, Like-New Phones for Lower Prices Tim | usagoldmines.com

Apple Complies With Recommendation to Remove 'Available Now' From Apple Intelligence Page Joe Rossig...

CATL unveils its new battery tech that charges in five minutes, offers huge range but doesn’t cost a...

1Password unveils new security and Agentic AI capabilities for XAM platform benedict.collins@futuren...

Lotus Panda hits unnamed government with bespoke hacking tools and malware | usagoldmines.com

Pakistan grants first VPN licenses in a bid to regulate VPN usage in the country chiara.castro@futur...

The Elder Scrolls 4: Oblivion Remastered is available right now on PC, PS5, Xbox Series X, and Serie...

Google Messages can now blur unwanted nudes, remind people not to send them Ryan Whitwam | usagoldmi...

You can play the Unreal-powered The Elder Scrolls IV: Oblivion remaster today Samuel Axon | usagoldm...

OpenAI’s newest AI models hallucinate way more, for reasons unknown | usagoldmines.com

T-Mobile Introduces 2 New “Experience” Plans With Several Upgrades, Price Lock Promise, But Taxes No...

What People Are Getting Wrong This Week: Fake News About Karoline Leavitt Stephen Johnson | usagoldm...

You Can Get Microsoft Office Professional Plus 2019 on Sale for $30 Right Now Pradershika Sharma | u...

Use This 3-Finger Trick to Quickly Share Photos on Apple Devices Tim Hardwick | usagoldmines.com

Sustainability Week: Why Africa’s sustainable future is the smartest investment | usagoldmines.com

Everything new on Max in May 2025, including the Oscar-winning drama The Brutalist rowan.davies@futu...

'He's holding a lot of the cards': Andor stars tease Luthen's 'important' role in the evolution of M...

Cyberpunk 2077 on the Nintendo Switch 2 will offer Nvidia's DLSS tech | usagoldmines.com

Garmin's ECG app is rolling out to two more countries stephen.warwick@futurenet.com (Stephen Warwick...

Cyberscam industry continues to thrive as raids fail to contain worldwide spread | usagoldmines.com

3 movies leaving Prime Video in April 2025 with over 85% on Rotten Tomatoes | usagoldmines.com

Netflix finally reveals the fate of one of its best shows by confirming that Heartstopper will end a...

10 essential Gmail ‘extra’ features I can’t live without | usagoldmines.com

Fastest VPN 2025: We identify the speediest performers | usagoldmines.com

This solar-powered Wi-Fi security camera is a whopping 50% off today | usagoldmines.com

Got a new PC? Make migration easy with this software bundle (67% off) | usagoldmines.com

Someone made ‘Windows’ for the Game Boy Color, and you can buy it | usagoldmines.com

How to Use 'Live Translate' on Your Pixel David Nield | usagoldmines.com

Blue Check Verification Is Coming to Bluesky Emily Long | usagoldmines.com

Apple Celebrating Earth Day in These Five Ways Joe Rossignol | usagoldmines.com

Apple's New 11th Gen iPad Hits Record Low Price of $319.99 on Amazon Mitchel Broussard | usagoldmine...

Google search engine monopoly could expand using AI, DOJ warns | usagoldmines.com

NYT Strands hints and answers for Wednesday, April 23 (game #416) | usagoldmines.com

NYT Connections hints and answers for Wednesday, April 23 (game #682) | usagoldmines.com

Quordle hints and answers for Wednesday, April 23 (game #1185) | usagoldmines.com

ChatGPT just leveled up – so why is Sam Altman comparing AI to the Renaissance, not a revolution? |...

Sustainability Week: Back to our roots - why trees are the original climate tech | usagoldmines.com

Leave a Reply