Contagious Interview (DPRK)
DPRK (North Korea) is a state-sponsored threat actor referenced in the provided content as operating or supporting multiple campaigns and malware families, including Contagious Interview, React2Shell activity, and related DPRK-aligned operations. Known aliases in the content include Contagious Interview and DPRK-aligned operators. The content describes an ongoing DPRK-linked Contagious Interview campaign that targets software developers, especially blockchain, Web3, and other job-seeking development professionals, through fake job interviews, staged hiring tasks, and trojanized meeting or assessment applications. In this activity, victims are instructed to execute malicious commands or install malicious packages and applications. The campaign has used more than 197 malicious npm packages with more than 31,000 downloads since October 10, and has relied on GitHub and Vercel infrastructure for payload delivery and command-and-control. Malware associated with this activity includes OtterCookie, described as a multistage infostealer and RAT, and BeaverTail, described as a downloader and stealer delivered via trojanized meeting apps and fake recruitment lures. Reported capabilities in the content include theft of credentials, cryptocurrency wallet data, clipboard contents, browser data, keystrokes, and screenshots. The content also attributes FlexibleFerret to DPRK-aligned operators as part of the Contagious Interview operation. FlexibleFerret is described as a macOS malware family distributed through fake recruitment sites such as evaluza[.]com and proficiencycert[.]com. Victims are socially engineered into running Terminal commands that trigger a multi-stage infection chain involving JavaScript stagers, shell scripts, architecture-specific payloads, persistence via a LaunchAgent, and a Go-based backdoor. Reported capabilities include credential theft, file exfiltration, OS command execution, and use of Dropbox APIs for exfiltration. The campaign is described as targeting macOS users, especially online job seekers, and as an evolution of earlier Contagious Interview activity. Additional DPRK-linked malware and operations mentioned in the content include EtherRAT, described as a novel Ethereum implant used in React2Shell attacks, and SpectralBlur, identified as DPRK malware analyzed in 2024. The content also notes that a malware campaign abused Microsoft VSCode Tasks to deliver Interview malware. Overall, the provided material portrays DPRK as a persistent nation-state actor using social engineering, software supply chain compromise, fake recruitment workflows, and multi-stage malware delivery to target developers and other users of strategic interest.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- technology
- blockchain
- crypto
Tradecraft
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Recent activity
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
DPRK is using a novel Ethereum implant called EtherRAT in attacks leveraging the React2Shell vulnerability.
The Contagious Interview campaign is a North Korean state-sponsored operation targeting software developers, especially in the blockchain and Web3 sectors, through fake job interviews and test assignments. The attackers use social engineering to lure victims and then deliver malicious npm packages to compromise developer environments, steal credentials, cryptocurrency, and other sensitive data, and establish persistent access for further exploitation.
Conducting credential theft and espionage campaigns against individuals using fake job recruitment lures to socially engineer targets into executing macOS malware (FlexibleFerret), which establishes persistence, exfiltrates credentials, and provides remote access.
DPRK-linked threat actors have developed stealer malware such as BeaverTail, distributed via trojanized meeting applications, targeting users for credential and data theft.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.