Dawn of Ninja Era: unmasking a malware distribution campaign linked to DPRK IT workers network

Thursday 15 October 16:30 - 17:00, Red room   

Naoki Takayama (Internet Initiative Japan)

In July 2026, we discovered and investigated a malware distribution campaign targeting online gamers and software developers in Japan. A threat actor group has leveraged a fake online game named "Ninja Era" as a lure, which has been conceived, designed, and developed using generative AI. Throughout diligent monitoring and analysis, we have obtained multiple related malware samples, insights from a data exfiltration platform, and even activity records of the threat actor group. By analysing the activity records, we have confirmed that the threat actor has a strong connection with the known DPRK IT workers network.

At the start of this talk, we outline the analysis of the "Ninja Era" game installer files and malicious payloads executed by them. The game installer executes multi-stage loader payloads, which leads to the execution of custom infostealer malware specifically targeting Telegram Messenger, and also modular .NET malware known as MoonPeak. Each payload observed was heavily obfuscated or encrypted, so we will showcase the methodologies used to analyse and extract IOCs including C2 server address. We will also showcase the comparison with the payload deployed by same threat actor group in past campaigns, which illustrates how threat actors evolve both their malware and TTPs as time progresses.

We will then discuss fake recruitment information posted by the threat actor on a Japanese crowdsourcing platform in August 2026. Fake recruitment information claimed that the development studio of "Ninja Era" was hiring software developers specialized in Solidity, Web3 Wallet, and smart contracts for developing an in-game economic system. We are highly confident that the purpose of this recruitment information was to lure job applicants to infect their computer with malware, based on conversations we observed between the threat actor and job applicants. We will provide an overview this fake recruitment campaign, alongside an analysis of documents, design data, and source codes hosted on the "Ninja Era" official website, which also contained malicious payloads executing MoonPeak.

Lastly, we will describe the threat group's background, characteristics of their attack flow, and internals of their infrastructure. We reveal how individuals engaged in the malware distribution campaign alongside activity as DPRK IT workers to gain illicit earnings. We have also identified the commonalities of payloads and infrastructures operated by the threat group, allowing us to pivot multiple in-the-wild malware samples with strong correlation. By analysing them in detail, we will showcase an effective countermeasures and detection methodologies, helping the audience to defend against similar attack campaigns. Moreover, we will introduce an analysis of the admin panel hosted on "Ninja Era" official website, revealing how the threat actor manages victims and exfiltrated data from Telegram Messenger.

 

 


Naoki-Takayama.jpg

Naoki Takayama

Naoki Takayama is a security researcher at Internet Initiative Japan, Inc. He specializes in reverse engineering, malware analysis, and digital forensics. As a member of IIJ-SECT, the private CSIRT of his company, he is engaged in threat research and incident response. His research focuses on malware and tactics used in APT campaigns targeting East Asia. He has spoken at multiple cybersecurity conferences including BSides Tokyo, FIRSTCON, JSAC and Virus Bulletin in the past.

X-thumbnail.jpg@mopisec

Back to VB2026 Programme page

Back to VB2026 conference page

Register for VB2026

Other VB2026 papers

Threat intelligence-driven clustering: identifying a new cyber-mercenary intrusion set

VB2026 presentation: Threat intelligence-driven clustering: identifying a new cyber-mercenary intrusion set, Maher Yamout and Fatih Şensoy

From hotel account compromise to guest payment fraud: the reservation hijack attack chain

VB2026 presentation: From hotel account compromise to guest payment fraud: the reservation hijack attack chain, Martin Chlumecký and Luis Corrons

Hunting LANDFALL: from overlooked images to state-linked mobile spyware

VB2026 presentation: Hunting LANDFALL: from overlooked images to state-linked mobile spyware, Itay Cohen

Gorbag: Orcs at the border

VB2026 presentation: Gorbag: Orcs at the border, Damien Schaeffer

Defeating indirect branching obfuscations in malware with Hex-Rays Decompiler

VB2026 presentation: Defeating indirect branching obfuscations in malware with Hex-Rays Decompiler, Georgy Kucherin

Discerning the invisible: a heuristic engine for behavioural inference in nation-state covert networks

VB2026 presentation: Discerning the invisible: a heuristic engine for behavioural inference in nation-state covert networks, Madeline Sedgwick

Kimwolf’s claws loom over 1.8 million firewalled Android devices worldwide

VB2026 presentation: Kimwolf’s claws loom over 1.8 million firewalled Android devices worldwide, Alex Turing

Paying the TOLL: how REF3927 turned 571 IIS servers into an SEO fraud network

VB2026 presentation: Paying the TOLL: how REF3927 turned 571 IIS servers into an SEO fraud network, Salim Bitam and Jia Yu Chan

Leveraging Landlock telemetry for Linux detection engineering

VB2026 presentation: Leveraging Landlock telemetry for Linux detection engineering, Guillaume Couchard and Erwan Chevalier

Targeting the elderly: from spoofing to persistence

VB2026 presentation: Targeting the elderly: from spoofing to persistence, Axelle Apvrille

The invisible warzone: competing botnets fighting over your smart TV

VB2026 presentation: The invisible warzone: competing botnets fighting over your smart TV, Asher Davila, Chris Navarrete & Doel Santos

Mac&Cheese: cooking up the Digit Stealer recipe

VB2026 presentation: Mac&Cheese: cooking up the Digit Stealer recipe, Kseniia Yamburh & Joan Garcia

How real-world malware disables EDR systems

VB2026 presentation: How real-world malware disables EDR systems, Holger Unterbrink

Newsjacking the world: tracking three months of uncovered APT operations disguised as global headlines

VB2026 presentation: Newsjacking the world: tracking three months of uncovered APT operations disguised as global headlines, Darrel Virtusio & Subhajeet Singha

Polling is the vulnerability: a case for event-driven cloud detection

VB2026 paper: Polling is the vulnerability: a case for event-driven cloud detection, Santiago Abastante

The edge is the enemy: hunting Chinese router relay networks

VB2025 presentation: The edge is the enemy: hunting Chinese router relay networks, Ryan Sherstobitoff

Unravelling Lumma Stealer’s protection stack: pushing static deobfuscation to its practical limit

VB2026 presentation: Unraveling Lumma Stealer’s protection stack: pushing static deobfuscation to its practical limit, Yuki Umemura

AI in malware: evolution and predicting the future of AI-driven attacks

VB2026 presentation: AI in malware: evolution and predicting the future of AI-driven attacks, Eli Smadja

The cyber saga: deconstructing the DPRK’s global synthetic IT workforce ecosystem

VB2026 presentation: The cyber saga: deconstructing the DPRK’s global synthetic IT workforce ecosystem, Anastasia Tikhonova

Tracing the bloodline of LLM-driven polymorphic malware: do GHOSTs leave footprints?

VB2026 presentation: Tracing the bloodline of LLM-driven polymorphic malware: do GHOSTs leave footprints? Chanbin Jeon, SeungBeom Lim & SuhMahn Hur

How LOLRMM, LOLDrivers and CertGraveyard map the attacker's favourite kill chain

VB2026 presentation: How LOLRMM, LOLDrivers and CertGraveyard map the attacker's favourite kill chain, Jose Enrique Hernandez & Nasreddine Bencherchali

Agent detection and response: safety on a token budget

VB2026 presentation: Agent detection and response: safety on a token budget, Václav Belák, Jakub Křoustek & Tomáš Ďuriš

Malwaremorphosis - breaking down a global multi-layer malvertising operation

VB2026 presentation: Malwaremorphosis - breaking down a global multi-layer malvertising operation, Ionuț Baltariu

I will find you and I will flag you: hunting malicious packages at scale

VB2026 presentation: I will find you and I will flag you: hunting malicious packages at scale, Christophe Tafani-Dereeper

Otter encyclopaedia: deep analysis of Otter family

VB2026 presentation: Otter encyclopaedia: deep analysis of Otter family, Rintaro Koike, Yuta Sawabe & Masaya Motoda

Break the silence: tracking Silent Lynx through exposed infrastructure

VB2026 presentation: Break the silence: tracking Silent Lynx through exposed infrastructure, Julian Ferdinand Vögele & Chi-en (Ashley) Shen

Operation FalseProof: PoC that bites back

VB2026 presentation: Operation FalseProof: PoC that bites back, Jiho Kim & Minyeop Choi

Transparency wars: exposing hidden biases in testing

VB2026 presentation: Transparency wars: exposing hidden biases in testing, Righard Zwienenberg & Luis Corrons

Snap, trigger, steal: SnappyClient and the art of trigger-based intrusions

VB2026 presentation: Snap, trigger, steal: SnappyClient and the art of trigger-based intrusions, Muhammed Irfan V A, Avinash Kumar & Nirmal Singh

Reverse engineering a multi-stage implant targeted Vietnamese organizations

VB2026 presentation: Reverse engineering a multi-stage implant targeted Vietnamese organizations, Minh Anh Luong

When malware talks back: real-time interaction with a threat actor during the analysis of Kiss Loader

VB2026 presentation: When malware talks back: real-time interaction with a threat actor during the analysis of Kiss Loader, Marvin Castillo & Arvin Jay Bandong

Free games, costly consequences: unravelling PiviGames’ hidden treasure malware

VB2026 presentation: Free games, costly consequences: unravelling PiviGames’ hidden treasure malware, John Rey Dador

Khmer Shadow: uncovering a targeted cyber espionage campaign against Cambodian military intelligence

VB2026 presentation: Khmer Shadow: uncovering a targeted cyber espionage campaign against Cambodian military intelligence, Subhajeet Singha

Practical ransomware detection on macOS (via maths, not AI)

VB2026 presentation: Practical ransomware detection on macOS (via maths, not AI), Patrick Wardle

From exclusive to widespread: the shifting exploitation dynamics of (zero-day) vulnerabilities before and after their (public) disclosure

VB2026 presentation: From exclusive to widespread: the shifting exploitation dynamics of (zero-day) vulnerabilities before and after their (public) disclosure, Kerstin Zettl-Schabath & Kritika Roy

The other side of the front: hunting Paper Werewolf's operations against Russia

VB2026 presentation: The other side of the front: hunting Paper Werewolf's operations against Russia, Nicole Fishbein

Meet ARES - an agentic reverse engineer that decrypts sophisticated ransomware encrypted files

VB2026 presentation: Meet ARES - an agentic reverse engineer that decrypts sophisticated ransomware encrypted files, Raviv Rachmiel

Disrupting the threat actor mythos: data-based insights into targeting, tooling, and the limits of AI in cybercrime

VB2026 presentation: Disrupting the threat actor mythos: data-based insights into targeting, tooling, and the limits of AI in cybercrime, Selena Larson & Daniel Blackford

Iberian Deception: Phishing Campaigns Targeting Tax and Traffic Authorities in Portugal and Spain

VB2026 presentation: Iberian Deception: Phishing Campaigns Targeting Tax and Traffic Authorities in Portugal and Spain, Natasha Márquez & Ghyorka Kpee

When wipers leave backups: an analysis of ArgonWiper’s encryption workflow

VB2026 presentation: When wipers leave backups: an analysis of ArgonWiper’s encryption workflow, Hyuna Lee & Hyoje Jo

Notoriously reluctant: continuing conversations with FBI and private sector defenders about disrupting cybercriminals through collaboration

VB2026 presentation: Notoriously reluctant: continuing conversations with FBI and private sector defenders about disrupting cybercriminals through collaboration, Sara Eberle & DeLynn Bettencourt Hammell

From dead malware to living adversaries: AI-powered digital twins for adaptive APT modelling

VB2026 presentation: From dead malware to living adversaries: AI-powered digital twins for adaptive APT modelling, Alexander Adamov & Anders Carlsson

The silent threat in your enterprise: SAP security

VB2026 presentation: The silent threat in your enterprise: SAP security, Anita Cwynar

BEAST: binary emulation and analysis simulation technology for advanced malware analysis and anti-forensic countermeasures

VB2026 presentation: BEAST: binary emulation and analysis simulation technology for advanced malware analysis and anti-forensic countermeasures, Bramwell Brizendine, Alexander Wood, Jared Sheldon & William Lochte

Spec-driven malware: turning markdown into threats

VB2026 presentation: Spec-driven malware: turning markdown into threats, Sven Rath

The invisible candidate: tracking the evolution of 'Un-tracked' GRITCASPIAN

VB2026 presentation: The invisible candidate: tracking the evolution of 'Un-tracked' GRITCASPIAN, Asli Koksal

DPRK-aligned threat operations: tradecraft, tooling, and detection patterns

VB2026 presentation: DPRK-aligned threat operations: tradecraft, tooling, and detection patterns, Wonkyeom Kim

Workshop: Collaborative attack modelling across CTI, Red Team, and SOC (MITRE)

VB2026 workshop: Collaborative attack modelling across CTI, Red Team, and SOC (MITRE)

TIPS: The next chapter

VB2026 TIPS presentation: The next chapter, Jiri Sejtko

TIPS: Collaboration in action: turning shared threat intelligence into coordinated defence

VB2026 TIPS presentation: Collaboration in action: turning shared threat intelligence into coordinated defence, Tuna Dabak

TIPS: From signal to shield: rapid collaboration to defend critical infrastructure during crisis

VB2026 TIPS presentation: From signal to shield: rapid collaboration to defend critical infrastructure during crisis, Madeline Sedgwick

TIPS: Harmonizing AI agents and human analysts in CTI - are CTI agents friends or rivals to junior analysts?

VB2026 TIPS presentation: Harmonizing AI agents and human analysts in CTI - are CTI agents friends or rivals to junior analysts? Takahiro Kakumaru

TIPS: Stairway to resilience: cybersecurity in good times, bad times, and everything between

VB2026 TIPS presentation: Stairway to resilience: cybersecurity in good times, bad times, and everything between Selena Larson, Jeannette Jarvis, Kathi Whitbey, Jeanette Miller Osborne

TIPS: Defending (against) the human layer: IoB in the real world

VB2026 TIPS presentation: Defending (against) the human layer: IoB in the real world Righard Zwienenberg, Kathi Whitbey, Samir Mody & Mienke

TIPS: STIX in action: proposed industry collaboration on sharing DigSig metadata

VB2026 TIPS presentation: STIX in action: proposed industry collaboration on sharing DigSig metadata, Samir Mody

TIPS: Ghosts in the chat: tracking GhostPairing from trusted message to linked-device takeover 

VB2026 TIPS presentation: Ghosts in the chat: tracking GhostPairing from trusted message to linked-device takeover, Michal Salat

TIPS: The art of fighting back

VB2026 TIPS presentation: The art of fighting back, Gabor Szappanos

TIPS: Wartime intelligence collection and collaboration

VB2026 TIPS presentation: Wartime intelligence collection and collaboration, Sergey Shykevich

Setting off into the wild blue yonder

VB2026 closing keynote: Setting off into the wild blue yonder, Saâd Kadhi

Operation RikiBox: the new threat actor with two novel persistence mechanisms

VB2026 presentation: Operation RikiBox: the new threat actor with two novel persistence mechanisms, Sojun Ryu

Hidden in the overlay - analysis of a backdoor leveraging encrypted overlay communications for ORB

VB2026 presentation: Hidden in the overlay - analysis of a backdoor leveraging encrypted overlay communications for ORB, Yuma Masubuchi

Under the surface: inside the evolving 10FXRAT campaign

VB2026 presentation: Under the surface: inside the evolving 10FXRAT campaign, Yoshihiro Ishikawa & Takuma Matsumoto

After the wipe: runtime root-secret recovery from JadePuffer/ ENCFORGE on Windows

VB2026 presentation: After the wipe: runtime root-secret recovery from JadePuffer/ ENCFORGE on Windows, Wei Gao

From seed to branch: inside DarkPlum's expansion to Ukraine

VB2026 presentation: From seed to branch: inside DarkPlum's expansion to Ukraine, Masaya Motoda, Shogo Hayashi & Rintaro Koike

Operation ASTERIX: software developer by day, crypto scammer by night

VB2026 presentation: Operation ASTERIX: software developer by day, crypto scammer by night, Anna Širokova & Jan Řečínský

Manufactured credibility: detecting fabricated Git history in an active software supply chain Campaign

VB2026 presentation: Manufactured credibility: detecting fabricated Git history in an active software supply chain campaign, George Karagiannidis & Evangelos Ganiaris

Dawn of Ninja Era: unmasking a malware distribution campaign linked to DPRK IT workers network

VB2026 presentation: Dawn of Ninja Era: unmasking a malware distribution campaign linked to DPRK IT workers network, Naoki Takayama

Ghost in the webmail: how TA488 learned to haunt your inbox

VB2026 presentation: Ghost in the webmail: how TA488 learned to haunt your inbox, Saher Naumaan

Inside a Sandworm attack: UAC-0099 access and a Yggdrasil-backed backdoor

VB2026 presentation: Inside a Sandworm attack: UAC-0099 access and a Yggdrasil-backed backdoor, Anton Cherepanov & Peter Strýček

Inside Popa: a day in the life of a residential proxy

VB2026 presentation: Inside Popa: a day in the life of a residential proxy, Carel Bitter

TIPS: From strategic collections to global and multifaceted ransomware response

VB2026 TIPS presentation: From strategic collections to global and multifaceted ransomware response, Gonçalo Ribeiro

Partner presentation: Gulp: exploring and overcoming the limits of modern DFIR

VB2026 partner presentation: Gulp: exploring and overcoming the limits of modern DFIR, Gabriele Zuddas, Mentat

Seeing through a straw: when the threat is bigger than your data

VB2026 keynote presentation: Seeing through a straw: when the threat is bigger than your data, Katie Nickels

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.