GapiUpdate Campaign: Web3 Interviews Delivering Multi-Payload Stealers
Score: 9/10

GapiUpdate Campaign: Web3 Interviews Delivering Multi-Payload Stealers

DPRK-nexus actors are using fake Web3 job interviews to deliver signed ClickOnce applications that deploy NeedleStealer, an unclassified Rust stealer, and a Go-based hVNC RAT.

Executive Summary

In July 2026, a sophisticated social engineering campaign targeted cryptocurrency professionals using fake recruiter personas on LinkedIn and Calendly-based interview lures. Victims were directed to a malicious technical assessment hosted on Google Apps Script, which functioned as a triage platform to deliver platform-specific malware. For Windows users, the campaign utilized signed Microsoft ClickOnce applications to bypass traditional security warnings and deploy a triple-payload bundle.

The attack chain involves a complex multi-stage loading process featuring a custom 'Vortex' authenticated shellcode container and modified Donut loaders. The final payloads include NeedleStealer, a high-capability Rust-based stealer, and a custom Go remote access trojan (RAT) with hidden VNC (hVNC) capabilities. These tools are designed for total credential harvesting, targeting not only browser data and wallets but also developer-specific secrets like AWS keys, GitHub tokens, and SSH material.

This activity shows significant overlap with established DPRK-nexus 'Contagious Interview' patterns and shared MaaS/traffer infrastructure. The impact is severe, involving immediate private key compromise and automated wallet draining. Organizations in the cryptocurrency and decentralized finance sectors should remain highly vigilant regarding unsolicited recruitment outreach that requires technical assessments or software installations.

Key Details

Threat Name

GapiUpdate Campaign

Affects

—

Adversary

DPRK

Malware/Tools

NeedleStealer, Odyssey Stealer, Donut

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance7
Enterprise Relevance9
Clarity & Structure10
Technical Depth10

Sources