Skip to content
SlowMist Warns of Lazarus Group's Social Engineering Attacks on Web3 Developers

SlowMist Warns of Lazarus Group's Social Engineering Attacks on Web3 Developers

Kucoin • April 24, 2026

SlowMist has issued a security alert stating that North Korea’s Lazarus group, through its HexagonalRodent faction, is using social engineering tactics such as “high-paying remote positions” and “recruitment for well-known projects” to trick Web3 developers into executing malicious code and stealing crypto assets. On March 9, 2026, a user with the same name as a fast-draft extension developer was infected with the OtterCookie malware, which was used to distribute additional malicious software. The attackers are also extensively using ChatGPT and Cursor to enhance their deception and impersonation capabilities.

Extracted Entities

Attack Types (2)

Companies (1)

Countries (1)

Malware (1)

Platforms (1)