INTEL_REPORT
Trend Micro Research · published 4/21/2026, 12:00:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories Our research on Void Dokkaebi’s operations uncovered a campaign that turns infected developer repositories into malware delivery channels. By spreading through trusted workflows, organizational codebases, and open-source projects, the threat can scale from a single compromise to a broader supply chain risk. Void Dokkaebi Uses Fake Job Interview Lure to Spread Malware via Code Repositories | T…
https://www.trendmicro.com/en_us/research/26/d/void-dokkaebi-uses-fake-job-interview-lure-to-spread-malware-via-code-repositories.html
sha256:2d7dd0bdf7a68a3c7c9f81c5a28cbfaddc67769432b9170daa2bf355885361cf
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| next.config.mjs |
| Open → |
| ip | 136.0.9.8 | Open → |
| ip | 154.91.0.196 | Open → |
| ip | 23.27.20.143 | Open → |
| ip | 85.239.62.36 | Open → |
| ip | 83.168.68.219 | Open → |
| ip | 166.88.4.2 | Open → |
| ip | 23.27.120.142 | Open → |
| domain | api.trongrid.io | Open → |
| domain | fullnode.mainnet.aptoslabs.com | Open → |