North Korean APT Group HexagonalRodent Steals $12M in Crypto from Web3 Developers Using AI-Powered Attacks

Gate News message, April 24 — A North Korean state-sponsored APT group dubbed HexagonalRodent has stolen over $12 million in cryptocurrency and NFTs from Web3 developers in the first quarter of 2026, according to cybersecurity firm Expel. The group compromised 2,726 developer devices and gained access to 26,584 crypto wallets.

The group primarily uses fake job postings on LinkedIn and Web3 recruitment platforms to lure job seekers into completing “skill tests” embedded with malicious code. When victims open project files in VSCode, the malware—including BeaverTail, OtterCookie, and InvisibleFerret—automatically executes, enabling credential theft, remote access, and reverse shell capabilities. The attackers also registered shell companies in Mexico to enhance credibility.

Notably, HexagonalRodent has heavily leveraged generative AI tools like ChatGPT and Cursor to develop malware, create fake company websites, and generate AI-powered executive profiles. The group recently conducted its first supply chain attack, successfully compromising a VSCode extension.

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.

Related Articles

The U.S. Department of Justice seizes $700 million in cryptocurrency and charges two Chinese nationals in connection with a Myanmar scam compound

According to an official announcement released by the U.S. Department of Justice (DOJ) on April 24, the Fraud Center Strike Force has announced several coordinated actions targeting Southeast Asian scam organizations, including filing criminal charges against two Chinese citizens who manage scam compounds in Myanmar, seizing more than $701.9 million in cryptocurrency allegedly used for money laundering, and shutting down a Telegram recruitment channel along with 503 scam domains.

MarketWhisper5m ago

OFAC Sanctions Cambodian Senator Over Crypto Scam Network

OFAC Sanctions Cambodian Senator Over Crypto Scam Network The U.S. Treasury's Office of Foreign Assets Control (OFAC) has sanctioned Cambodian senator Kok An, who is accused of controlling "scam compounds" throughout Cambodia that have defrauded Americans. OFAC designated An and 28 other

CryptoFrontier14m ago

Senator Warren Questions Erebor Crypto Bank Approval Process, Citing Political Concerns

Gate News message, April 24 — U.S. Democratic Senator Elizabeth Warren raised questions about the regulatory approval process for cryptocurrency bank Erebor, citing concerns that the institution obtained a banking license within months. According to a fundraising document obtained by Warren's

GateNews19m ago

U.S. sanctions Cambodian officials’ billion-dollar scam resort! Tether freezes more than $344 million in USDT

The U.S. Treasury Department and the Department of Justice have recently launched a joint law enforcement action targeting “pig butchering” romance scams involving cryptocurrencies that have become increasingly rampant in Southeast Asia. In an official announcement, the government has imposed sanctions on Cambodian Senator Kok An and 28 individuals and entities within his criminal network, accusing them of using political influence and their network of casino compounds to shelter large-scale fraud and human trafficking activities. Estimates indicate that these scam operations have led to losses for U.S. residents of as much as $10 billion in a single year. In conjunction with this crackdown, the stablecoin issuer Rether has also frozen more than $344 million in digital assets involved in the case. Romance “Pig Butchering” scams: U.S. residents lose over $10 billion in a single year In recent years, multinational criminal organizations based in Southeast Asia have made extensive use of the scam method known as “Pig Butchering.” Scammers will, through social media or messaging apps, spend months

ChainNewsAbmedia25m ago

U.S. Army Soldier Arrested for Using Classified Intel to Bet on Maduro's Capture on Polymarket

Gate News message, April 24 — The U.S. Department of Justice has arrested active-duty Army soldier Gannon Ken Van Dyke, 38, on charges of using confidential information to place bets on Polymarket, a prediction market, regarding former Venezuelan President Nicolás Maduro's capture. Van Dyke particip

GateNews31m ago

Gate Daily Report (April 24): US Treasury sanctions Cambodian crypto “pig butchering” scams; Tether mints an additional 1 billion USDT

Bitcoin (BTC) rebound momentum is weakening, with a temporary quote around $78,030 as of April 24. The U.S. Treasury Department’s Office of Foreign Assets Control (OFAC) sanctioned a Cambodian politician linked to a crypto “pig butchering” scam center. Tether issued another 1 billion USDT on the Ethereum network; over the past 5 days, it has issued a total of 3 billion USDT on the Ethereum network.

MarketWhisper3h ago
Comment
0/400
No comments