UNK_DeadDrop
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3BG1Gf…cU4xSummary
UNK_DeadDrop is a threat cluster designation assigned by Proofpoint Threat Research to a likely North Korea-aligned cyber threat actor that conducted a sustained phishing campaign targeting software developers between April and May 2026. The campaign used fake job offers and code-review requests linked to malicious GitHub and GitLab repositories to deliver cross-platform malware designed to steal cryptocurrency wallets and developer credentials. The actor is tracked as a distinct cluster from the previously documented Contagious Interview operation, though significant tactical and objective overlap is noted.
Connected Entities
1 entities · 10 linked investigationsTimeline(4 events)
April 2026
UNK_DeadDrop campaign begins. Proofpoint observes the first phishing emails using fake developer job offer lures linking to malicious GitHub repositories. Exact start date within April 2026 not publicly specified.
Proofpoint Threat ResearchMay 2026
Campaign lures shift in later May 2026 to peer code-review requests, with attackers posing as representatives of fictional cryptocurrency and AI firms Pulsynk and Trixauvex, as well as ERC-4626 smart-contract testing and AI payment agent project themes.
Proofpoint Threat Research31 May 2026
By the end of May 2026, UNK_DeadDrop had sent more than 250 phishing emails targeting individuals at approximately 100 organizations over the six-week campaign window.
The Register8 June 2026
Proofpoint publishes public threat intelligence report disclosing the UNK_DeadDrop campaign, its techniques, impersonated companies, and likely North Korean attribution. Coverage follows from The Register, Infosecurity Magazine, SC Media, TechRadar, and other outlets.
Proofpoint Threat ResearchDecision Log
- hash: EeSvjxD5e9qtQGi7z2s5wT7u1enFCsuXBVaAR71SE7ok
- hash: Dn7j9CkEzRV16iSE4ZjHjjBZQsq4Gi5TH3DrP7SWNaCb
- hash: C2h99RyykMFyeRre4CU7BkbLPe1XijsAP1tro75n1VGN
- hash: DisCcFjsLgY9ojYrB2tFECddPtu2c9Cor7YKuFCDz9H1
- hash: 14R2yhiAZKNKbkUewYUjpQGvXsN6u7XyXz8d78kaM7xx
This investigation is cryptographically anchored to the Solana blockchain (5 events). 14 of 14 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 6/14/2026, 11:03:15 PM
last updated: 7/26/2026, 11:10:23 PM
3 viewsavoid.net — verified advice for a post-truth world