Last seven days
- First activity
- Sep 6, 2026
- Last activity
- Sep 11, 2026
- Feed role
- C2 / Distribution
- Host form
- 12 IP / 60 hostnames
Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster.
Profile source: Mallory opens in a new tabOverlord
Overlord is an open-source Go command-and-control framework used in a 2026 developer-targeting phishing campaign tracked by Proofpoint as UNK_DeadDrop and assessed as likely North Korea-aligned, with noted overlaps to the Contagious Interview activity cluster. In the observed campaign, attackers delivered malicious GitHub and GitLab repositories via fake job offers, code review requests, and technical testing lures. The repositories abused hidden .vscode/tasks.json files to trigger execution when opened in Visual Studio Code or Cursor; Cursor reportedly executed the task silently, while VS Code prompted for approval. On macOS and Linux, attackers deployed Go-based Overlord RAT binaries and used them to maintain persistent WebSocket command-and-control connectivity, including to 23.137.105[.]75:5173. The malware was cross-platform overall, with Windows using a separate JavaScript/Python infostealer chain rather than an Overlord binary. Proofpoint reported custom Overlord modules named browserlogin, companywallet, and cleanup. Observed capabilities associated with the Overlord-based macOS and Linux payloads included remote access, persistence via a malicious VSIX extension disguised as google-update-support.vsix, theft of browser credentials, browser wallet extension data, standalone cryptocurrency wallet directories, browser cookies, and anti-forensic cleanup. On macOS, a secondary binary named darwin-password-prompt displayed a fake system password dialog to capture the user password, after which the malware modified Keychain access controls and extracted secrets including Safe Storage keys from browsers such as Chrome, Brave, Edge, Opera, Vivaldi, Arc, Yandex, and Chromium. On Linux, the malware used Zenity to present a fake credential prompt and attempted to extract secrets from GNOME Keyring using secret-tool or Python D-Bus methods. Stolen data was compressed into ZIP archives and exfiltrated to attacker-controlled infrastructure, including 23.137.105[.]75:5173.
C2 tracking
Derp observations, rolling seven-day window
Samples
4a54d34162a092947aba1269caf2f92bb2d210fa27f728164fa866d84f836174 f1fe5986366a06af9ef7e9f36a6678784afc7cdcc167b96a13efd3c7014ed033 05dbb515120ec8a6a453c91833eacf432e67ffe89fd650ac704eefc6bf8de290 32ead15908ca61088701ec6ee4c692658585746bafb52cce23c047d035fc91a5 40b643468356c0fd751893647ad0dc9e2a0019427e4f5f0e2f6e559efcecb977 f270a80b90acb4302bb29b2f4c7436f6d7eedc4738ca63351f59f22bd59ce28d f6c46c325441c6407ee6a7ccbc322ce04d4b499085ed80e1c3a86431d647610d b35e76ca0e97f8cef1bf00395af39d35a909e38a30548633864a1a35fb386412 2c8fc86e59faec2ae3057692e21d51acebf3abf95e755883aaa3a0d2dd61913a 647b3f8323189a74baaf009de952bdd7a38203fce0d4743eb8def16431d8e897 Reported operators
The malware deployed through this campaign is cross-platform, capable of running on macOS, Linux, and Windows. It leverages an open-source Go framework called Overlord to maintain persistent connections to a command-and-control server.
On Linux and macOS systems, the attacker leverages an open-source command-and-control (C2) framework called Overlord, deploying Go binaries with remote access trojan (RAT) capabilities that establish a persistent WebSocket connection to the attackerโs servers.
MITRE ATT&CK
Derp wouldn't exist without the work these projects do for the security community. We rely on their data sources to improve the quality and depth of what we publish. Thank you, we're genuinely grateful.