Last seven days
- First activity
- Jul 14, 2026
- Last activity
- Jul 20, 2026
- Feed role
- C2 / Distribution
- Host form
- 13 IP / 7 hostnames
Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster.
Profile source: Mallory opens in a new tabOverlord
Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster. In the observed campaign, attackers delivered malicious GitHub and GitLab repositories via fake job offers, code review requests, and technical testing lures. The repositories abused hidden .vscode/tasks.json files to trigger execution when opened in Visual Studio Code or Cursor; Cursor reportedly executed the task silently, while VS Code prompted for approval. On macOS and Linux, attackers deployed Go-based Overlord RAT binaries and used them to maintain persistent WebSocket command-and-control connectivity, including to 23.137.105[.]75:5173. The malware was cross-platform overall, with Windows using a separate JavaScript/Python infostealer chain rather than an Overlord binary. Proofpoint reported custom Overlord modules named browserlogin, companywallet, and cleanup. Observed capabilities associated with the Overlord-based macOS and Linux payloads included remote access, persistence via a malicious VSIX extension disguised as google-update-support.vsix, theft of browser credentials, browser wallet extension data, standalone cryptocurrency wallet directories, browser cookies, and anti-forensic cleanup. On macOS, a secondary binary named darwin-password-prompt displayed a fake system password dialog to capture the user password, after which the malware modified Keychain access controls and extracted secrets including Safe Storage keys from browsers such as Chrome, Brave, Edge, Opera, Vivaldi, Arc, Yandex, and Chromium. On Linux, the malware used Zenity to present a fake credential prompt and attempted to extract secrets from GNOME Keyring using secret-tool or Python D-Bus methods. Stolen data was compressed into ZIP archives and exfiltrated to attacker-controlled infrastructure, including 23.137.105[.]75:5173.
C2 tracking
Derp observations, rolling seven-day window
Samples
b7dfd524b305f476eebf5fc05c4689ed105df44e66353b0d21212a2192c9c26c 4320692c3d8740441eddb60c5fece7d15cb5fbb8ca1e4eb7199745223459878a 90694c0795f6100a78cd641568e2ed07f17b2ed6d20d5fcb52c1f5b5b4f99e78 1d4da8cc24dcc9d8fcea103c3b705323014d1e908427766cf07df98365eddb06 65a786d538da768d9bab96c16f4bfe9fb908ca13d5b907f3c71c70744747ac50 a89676aa3bfb08a68ac0a668853e0f56512632e3034743d2771d476444c498e1 d08e92b1c40a589e06984695f8fecf7ff2e8466359058552051c9613c718b5ff dc5ee368e6ef268c678c4b6acbbf2dc7fe100d1e0c4bb92b79c80c52c9cc74c7 4733c2d10010570f9f01c54d8478e04aee93ae237916d42f22f48b79182c78a4 4c3148876090c09dab618b50f9a2b5a9c83bdfdebfb034a74fd542b144a3105b Reported operators
The malware deployed through this campaign is cross-platform, capable of running on macOS, Linux, and Windows. It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.
On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attackerโs servers.
MITRE ATT&CK
Reporting
The malware deployed through this campaign is cross-platform, capable of running on macOS, Linux, and Windows. It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.
On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attackerโs servers.
The infection chain begins with emails containing links to actor-controlled GitHub repositories hosting malicious scripts that result in the execution of cross-platform malware for macOS, Linux, and Windows, including an open-source Go framework named Overlord.
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.