Crypto Developers Targeted by Python Malware Disguised as Coding Challenges

A malicious effort targeting developers to distribute new stealer malware under the pretense of a coding assignment has been linked to the North Korean-affiliated threat actor suspected of being responsible for the huge Bybit attack in February 2025.

Palo Alto Networks Unit 42 has linked the behavior to a hacker collective it monitors as Slow Pisces, also known as UNC4899, PUKCHONG, TraderTraitor, and Jade Sleet.

According to security researcher Prashil Pattni, Slow Pisces interacted with bitcoin engineers on LinkedIn by pretending to be prospective employers and sending malware disguised as coding challenges. For these tasks, developers must execute a corrupted code that uses malware that we have termed RN Loader and RN Stealer to infect their systems read more about Crypto Developers Targeted by Python Malware Disguised as Coding Challenges.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *