Find notable cyber news and cases, enriched with sources, timelines, and signals.

UNK_DeadDrop developer phishing campaign using fake job and code-review lures

Campaign
First reported
Last updated
Happening score
H score 30
1 unique sources, 1 articles

Summary

Hide ▲

A UNK_DeadDrop phishing campaign sent more than 250 emails to software developers at almost 100 organizations, using fake job and code-review lures to steal cryptocurrency and credentials. The operation targeted mostly US-based workers in technology, education, and finance, with a focus on cryptocurrency firms. It relied on GitHub/GitLab repositories, a hidden tasks.json file, and editor execution in VS Code or Cursor to deploy payloads across macOS, Linux, and Windows.

Related Happenings

JINX-0164 cryptocurrency recruitment-lure campaign

Campaign
H score39 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: A JINX-0164 campaign is targeting cryptocurrency firms and developers with LinkedIn recruiter lures, a fake meeting-and-fix workflow, and macOS malware to steal cr...

AUDIOFIX and MiniRAT macOS malware activity

Malware Activity
H score34 First: 28.05.2026 10:54 Last: 28.05.2026 10:54 Sources 1

About this happening: The AUDIOFIX and MiniRAT malware activity is targeting cryptocurrency firms and developer infrastructure on macOS with LinkedIn recruiter lures, a fake mee...

GlassWorm supply-chain malware activity

Malware Activity
H score22 First: 27.05.2026 14:48 Last: 27.05.2026 14:48 Sources 1

About this happening: The GlassWorm malware activity is now under a coordinated C2 disruption, reducing its ability to deliver new instructions and payloads to infected developer systems. The o...

Famous Chollima PromptMink supply-chain campaign targeting Web3 developers

Campaign
H score44 First: 29.04.2026 17:43 Last: 29.04.2026 17:43 Sources 1

About this happening: The PromptMink campaign is widening Famous Chollima's supply-chain intrusion playbook by pushing tainted npm packages into developer environments and stealing secrets....

Prt-scan GitHub pull_request_target supply-chain campaign

Campaign
H score45 First: 07.04.2026 00:38 Last: 07.04.2026 00:38 Sources 1

About this happening: The prt-scan campaign used AI-assisted automation to scale a broad GitHub supply-chain operation, increasing risk for repositories configured with `pull_request_target...

Timeline

  1. 08.06.2026 18:00 2 articles · 1mo ago

    Proofpoint tracks UNK_DeadDrop developer phishing campaign

    Initial Disclosure

    Proofpoint reported UNK_DeadDrop as a likely North Korean campaign that sent more than 250 phishing emails in April and May 2026 to software developers at almost 100 organizations, using fake job and code-review lures, GitHub/GitLab repositories, and malicious tasks.json execution in VS Code or Cursor to steal cryptocurrency and credentials.

    Show sources