Last seven days
- First activity
- Jul 23, 2026
- Last activity
- Jul 29, 2026
- Feed role
- C2 / Distribution
- Host form
- 20 IP / 13 hostnames
Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster.
Profile source: Mallory opens in a new tabOverlord
Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster. In the observed campaign, attackers delivered malicious GitHub and GitLab repositories via fake job offers, code review requests, and technical testing lures. The repositories abused hidden .vscode/tasks.json files to trigger execution when opened in Visual Studio Code or Cursor; Cursor reportedly executed the task silently, while VS Code prompted for approval. On macOS and Linux, attackers deployed Go-based Overlord RAT binaries and used them to maintain persistent WebSocket command-and-control connectivity, including to 23.137.105[.]75:5173. The malware was cross-platform overall, with Windows using a separate JavaScript/Python infostealer chain rather than an Overlord binary. Proofpoint reported custom Overlord modules named browserlogin, companywallet, and cleanup. Observed capabilities associated with the Overlord-based macOS and Linux payloads included remote access, persistence via a malicious VSIX extension disguised as google-update-support.vsix, theft of browser credentials, browser wallet extension data, standalone cryptocurrency wallet directories, browser cookies, and anti-forensic cleanup. On macOS, a secondary binary named darwin-password-prompt displayed a fake system password dialog to capture the user password, after which the malware modified Keychain access controls and extracted secrets including Safe Storage keys from browsers such as Chrome, Brave, Edge, Opera, Vivaldi, Arc, Yandex, and Chromium. On Linux, the malware used Zenity to present a fake credential prompt and attempted to extract secrets from GNOME Keyring using secret-tool or Python D-Bus methods. Stolen data was compressed into ZIP archives and exfiltrated to attacker-controlled infrastructure, including 23.137.105[.]75:5173.
C2 tracking
Derp observations, rolling seven-day window
Samples
fe91696e2991e634f4f7ce12a55a5d552cbf0d6117eaed3ad5fc3914d7e11a25 39d1a0eb227d6b171d66a7ddd79c8462cf4ca045c5ab30dddda6db6e51aa7e5c 427e37feb774625dd85776a6157435a437527ba870d4132d120efb077e5910dc 4ad0f60ec579e1b08137b6b0ea6f28a823935468a65dd405e5202a89019c63c8 9f95ad760d281ed2b9bdc6cfccdc957df83539df6ab6980a3396b6d6df959362 d6232cdb74f63e8051c8f8acca84bbd350d57741adcff80622c7cc6814263ac0 e13f71a6d08f1371a2d8acf2e0b093e3a59e66b778f824d184a2e5e4632be221 b7a305724bb96360a9a3e8d789fa5465bc577fbe5c8672702e7d199ebfbc1613 4a0c5764d62b2aebcd590aa4ee304546ce543bf3065affc4315c42e321758d86 56a9f506301ce1757fe0e76b210d1ca541d0fcf4212d15bcaec7189031e7211b Reported operators
The malware deployed through this campaign is cross-platform, capable of running on macOS, Linux, and Windows. It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.
On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attackerโs servers.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.