Be careful with the encoders! North Korea’s threat group wants to steal its cryptocurrency by challenging it in a programming confrontation


  • Slow Pisces addresses cryptography developers with a bad code disguised as stock analysis tools
  • The malicious code hides in sight, using YAML github and deerialization tricks
  • The victims install without knowing it Rn Loader and RN Stealer through manipulated python repositories

A group of North Korea computer pirates known as Slow Pisces has launched a sophisticated campaign aimed at developers in the cryptocurrency sector through LinkedIn.

The group, also known as merchant or Aguanieve Jade, is made by recruiters to attract victims with apparently genuine job offers and coding challenges, only to infect their systems with the malicious code of Python and Javascript.

Leave a Comment

Your email address will not be published. Required fields are marked *