North Korean TraderTraitor group plants malware on Indian IT services engineer via fake recruiter coding test

The intrusion followed the group's documented pattern of posing as technology recruiters. The targeted engineer received what appeared to be a take-home coding test; embedded in the test was a file pointing to lookalike HashiCorp web addresses, and running a standard setup command downloaded the malware. SentinelLABS uncovered several previously undocumented variants of the test during its investigation.

Once installed, the malware remained persistent for more than two months. A notable behaviour the researchers documented was that the payload stayed dormant whenever Cursor, an AI coding assistant the engineer used, was closed. SentinelLABS assessed this as a deliberate evasion mechanism tied to the victim's working patterns.

One candidate who encountered a similar test identified a suspicious URL embedded in the instructions, removed it, and assumed it was an intentional security-awareness check from the recruiter. This suggests the approach is broad enough that at least some targets are treating the malicious element as an expected part of a legitimate assessment.

One day after LayerZero published details of the KelpDAO breach, the attackers replaced the malware with a stripped-down version and deleted the originals, a response to public disclosure that indicates active operational monitoring by the group.

SentinelLABS researcher Alex Delamotte, working with Google's Nick Simonian, authored the full report. The researchers note that the expansion to an IT services provider signals a shift toward software supply chain exposure, with developers' laptops identified as high-value initial access targets.

To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter

More News