Skip to content
Malware family

Overlord

Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster.

Profile source: Mallory opens in a new tab

Overlord

Family profile

Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster. In the observed campaign, attackers delivered malicious GitHub and GitLab repositories via fake job offers, code review requests, and technical testing lures. The repositories abused hidden .vscode/tasks.json files to trigger execution when opened in Visual Studio Code or Cursor; Cursor reportedly executed the task silently, while VS Code prompted for approval. On macOS and Linux, attackers deployed Go-based Overlord RAT binaries and used them to maintain persistent WebSocket command-and-control connectivity, including to 23.137.105[.]75:5173. The malware was cross-platform overall, with Windows using a separate JavaScript/Python infostealer chain rather than an Overlord binary. Proofpoint reported custom Overlord modules named browserlogin, companywallet, and cleanup. Observed capabilities associated with the Overlord-based macOS and Linux payloads included remote access, persistence via a malicious VSIX extension disguised as google-update-support.vsix, theft of browser credentials, browser wallet extension data, standalone cryptocurrency wallet directories, browser cookies, and anti-forensic cleanup. On macOS, a secondary binary named darwin-password-prompt displayed a fake system password dialog to capture the user password, after which the malware modified Keychain access controls and extracted secrets including Safe Storage keys from browsers such as Chrome, Brave, Edge, Opera, Vivaldi, Arc, Yandex, and Chromium. On Linux, the malware used Zenity to present a fake credential prompt and attempted to extract secrets from GNOME Keyring using secret-tool or Python D-Bus methods. Stolen data was compressed into ZIP archives and exfiltrated to attacker-controlled infrastructure, including 23.137.105[.]75:5173.

C2 tracking

Seven-day C2 activity

Derp observations, rolling seven-day window

Observed infrastructure

Last seven days

First activity
Jul 14, 2026
Last activity
Jul 20, 2026
Feed role
C2 / Distribution
Host form
13 IP / 7 hostnames

Leading locations

  • US7
  • DE4
  • RU2
  • CH1
  • FR1
  • NL1
  • PL1
  • SI1

Leading providers

  • Cloudflare, Inc.3
  • Yandex.Cloud LLC2
  • 12651980 CANADA INC.1
  • 1337 Services GmbH1
  • aurologic GmbH1
  • CatalystVM LLC1

Infrastructure traits

  • Hosting 17
  • Anycast 3
  • Proxy 1

Samples

Recent associated samples

Reported operators

Threat actors

2 named in public reporting
Contagious Interview

The malware deployed through this campaign is cross-platform, capable of running on macOS, Linux, and Windows. It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.

UNK_DeadDrop

On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attackerโ€™s servers.

MITRE ATT&CK

Overlord in ATT&CK

38 distinct techniques

Reporting

Research mentioning Overlord

We appreciate you

Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.