IDE Attack Prevention
GitLab Threat Intelligence Team reveals North Korean tradecraft

GitLab Threat Intelligence Team reveals North Korean tradecraft

2/19/2026 · Oliver Smith

What this post added

This post details North Korean threat actors' tradecraft, including the use of JavaScript-based malware (BeaverTail, Ottercookie), custom obfuscation techniques, abuse of legitimate services for payload hosting (e.g., Vercel), and the use of VS Code tasks for malware execution. It also highlights the parallel operation of distinct threat actor teams and the technical proficiency variations observed.

Read the original post ↗