HexagonalRodent is a threat group targeting Web3 developers with social engineering to steal cryptocurrency assets.
Analyst brief
HexagonalRodent is a threat actor targeting Web3 developers to steal crypto assets, leveraging social engineering tactics like fake job offers. Their main TTPs include NodeJS-based toolkits BeaverTail and OtterCookie, the Python-based RAT InvisibleFerret, backdooring skills assessments via VSCode's tasks.json feature, and executing a supply chain attack through the compromised 'fast-draft' VSX extension. Defenders should focus on preventing opportunistic exfiltration of credentials and crypto wallets, particularly scrutinizing development environments and VS Code extensions.
HexagonalRodent
unknown
HexagonalRodent targets Web3 developers to steal crypto assets, employing social engineering tactics such as fake job offers. They utilize malware like BeaverTail and OtterCookie, both NodeJS-based toolkits, and InvisibleFerret, a Python-based RAT, to execute their attacks. Their TTPs include backdooring skills assessments via VSCode's tasks.json feature and conducting opportunistic exfiltration of credentials and crypto wallets. The group has also engaged in a supply chain attack, compromising the 'fast-draft' VSX extension to install malware.
What specific techniques has the HexagonalRodent group used to target VSCode users?+
HexagonalRodent backdoors skills assessments via VSCode's tasks.json feature and has executed a supply chain attack by compromising the 'fast-draft' VSX extension.
What are the primary malware tools used by HexagonalRodent?+
The group's main malware tools include the NodeJS-based BeaverTail and OtterCookie, as well as the Python-based InvisibleFerret RAT.