Contagious Interview is a North Korea-aligned threat activity cluster centered on social engineering of software developers and other technical professionals through fraudulent job offers, interview processes, coding tests, and recruiter impersonation. The operation is widely associated with DPRK state interests and is linked by multiple vendors to the Lazarus ecosystem or adjacent DPRK intrusion sets. Commonly cited overlapping or related names include UNC5342, Famous Chollima, Void Dokkaebi, DeceptiveDevelopment, Tenacious Pungsan, and Gwisin Gang, although reporting does not always treat all of these labels as perfectly coextensive. Malware and sub-clusters repeatedly associated with the activity include BeaverTail, InvisibleFerret, OtterCookie, JADESNOW, PylangGhost, and in some reporting ContagiousDrop infrastructure and related supply-chain tooling. The cluster primarily targets software developers, especially individuals working in cryptocurrency, blockchain, decentralized finance, and broader technology sectors. Victims are approached through professional networking and freelance platforms, email, chat applications, fake recruiter personas, fabricated companies, and cloned hiring or assessment websites. Lures commonly involve technical assessments, repository reviews, interview scheduling, fake conferencing or camera-driver troubleshooting, and requests to clone or execute code in normal developer workflows. The campaign has also expanded into software supply-chain abuse through malicious npm and other package ecosystem uploads, trojanized repositories, and abuse of development tools and editor automation. Operational objectives are predominantly financial, especially theft of cryptocurrency wallets, browser-stored credentials, authentication material, and other sensitive data that can be monetized. Reporting also indicates a secondary espionage and access objective: compromising developers and technical staff to gain footholds in technology companies, harvest intellectual property, and support follow-on intrusion activity. Some reporting links the broader ecosystem around these operators to DPRK revenue-generation efforts and to fraudulent remote-worker schemes in which North Korean operatives or facilitators obtain employment under false identities. Tradecraft is characterized by persistent social engineering, rapid infrastructure replacement, and cross-platform malware delivery against Windows, macOS, and Linux. Initial access often relies on malicious JavaScript, Node.js, Python, or native components embedded in coding challenges, package dependencies, fake interview applications, or hidden project automation. Follow-on payloads commonly perform host reconnaissance, browser credential theft, wallet theft, keychain or keyring access, clipboard theft, keylogging, remote shell access, persistence through legitimate remote-management software or malicious extensions, and staged download of additional implants. Several campaigns show strong emphasis on living within expected developer behavior, such as opening repositories in IDEs, installing dependencies, or executing troubleshooting commands. A notable evolution in this cluster is the use of blockchain-backed command-and-control or payload delivery, often described as EtherHiding. Associated tooling has used public smart-contract platforms to store or resolve encrypted payload locations or command infrastructure, improving resilience against traditional domain takedowns and blocking. Reporting also highlights recurring use of package registries, source-code hosting platforms, cloud services, and collaborative tools for lure delivery, staging, and operational coordination. The activity demonstrates sustained operational tempo, broad victimology, and iterative malware development. It has been observed abusing fake job ecosystems at scale, publishing large numbers of malicious packages, and adapting delivery mechanisms across social platforms, email, repositories, and development environments. Overall, Contagious Interview represents a mature DPRK-aligned intrusion and theft campaign focused on developers as both direct financial targets and strategic access vectors into the cryptocurrency and technology sectors.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
68 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 malware families attributed to this actor across reporting.
33 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
534 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korea-aligned intrusion set mentioned only as historical comparison for blockchain-related tradecraft.
North Korean state-backed intrusion activity focused on the tech sector, including posing as remote IT workers and recruiters to infiltrate companies, steal intellectual property and sensitive information, extort victims, and target blockchain developers to steal cryptocurrency.
Runs two related campaigns: the IT Worker scheme to obtain salaries via fraudulent insider employment, and Contagious Interview targeting developers with fake job lures and coding tests that lead to infostealing malware and cryptocurrency theft. The group also uses Google Docs to host and update malicious job adverts, coding assessments, and proxy interviewee recruitment materials.
A previously known threat actor cluster that overlaps strongly with UNK_DeadDrop and is associated in the content with North Korea-aligned developer-targeting social engineering activity.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.