Not only DPRK. A vibe-coded phishing frontend for Microsoft Teams, found in the wild.
With the proliferation of capable, unrestricted LLMs, we often observe unaffiliated threat actors deploying fully vibe-coded malware infrastructure. In this example, an endpoint misconfiguration exposed the phishing kit's assets along with the LLM's comments. Interestingly, the threat actor most likely framed the task as a benign development job - a custom video conferencing platform called "Lassy Meet" - traces of which can also be found on the suspicious GitHub organization that also appears to be LLM-automated.
However, the comments reveal the intent.
IOCs:
223.165.6[.]141
netwitz.zoom01[.]us
teams.mlcrosoff[.]com
github[.]com/altosecteam-org