Gate News message, April 24 — A North Korean state-sponsored APT group dubbed HexagonalRodent has stolen over $12 million in cryptocurrency and NFTs from Web3 developers in the first quarter of 2026, according to cybersecurity firm Expel. The group compromised 2,726 developer devices and gained access to 26,584 crypto wallets.
The group primarily uses fake job postings on LinkedIn and Web3 recruitment platforms to lure job seekers into completing "skill tests" embedded with malicious code. When victims open project files in VSCode, the malware—including BeaverTail, OtterCookie, and InvisibleFerret—automatically executes, enabling credential theft, remote access, and reverse shell capabilities. The attackers also registered shell companies in Mexico to enhance credibility.
Notably, HexagonalRodent has heavily leveraged generative AI tools like ChatGPT and Cursor to develop malware, create fake company websites, and generate AI-powered executive profiles. The group recently conducted its first supply chain attack, successfully compromising a VSCode extension.