Back Kucoin SlowMist Warns of Lazarus Group's Social Engineering Attacks on Web3 Developers
SlowMist has issued a security alert stating that North Korea’s Lazarus group, through its HexagonalRodent faction, is using social engineering tactics such as “high-paying remote positions” and “recruitment for well-known projects” to trick Web3 developers into executing malicious code and stealing crypto assets. On March 9, 2026, a user with the same name as a fast-draft extension developer was infected with the OtterCookie malware, which was used to distribute additional malicious software. The attackers are also extensively using ChatGPT and Cursor to enhance their deception and impersonation capabilities.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
