DeceptiveDevelopment and North Korean IT workers: from primitive crypto theft to sophisticated AI-based deception

No ratings

Presented at VB2025 Berlin by

DeceptiveDevelopment, also known as ContagiousInterview, is a North Korea-aligned threat actor operating since late 2023, actively focused on cryptocurrency theft, primarily targeting freelance developers. This threat actor shares some notable TTP similarities with those of other North Korea-aligned groups, such as Lazarus and Moonstone Sleet – namely the use of social engineering, faux recruiter profiles on social media, and delivering malware disguised as job offers. What makes DeceptiveDevelopment unique is its specific targeting of freelance developers and individuals associated with cryptocurrency and blockchain projects. The intention behind this is twofold – theft of the cryptocurrency wallets belonging to these individuals and gaining access to larger projects and institutions these developers may be a part of, potentially for further intrusion.