Contagious Interview is a North Korea-aligned threat activity cluster centered on social-engineering software developers and job seekers, especially individuals involved in cryptocurrency, blockchain, and broader technology roles. The operation is widely associated with UNC5342 and has also been linked in overlapping reporting to aliases and malware families including BeaverTail, InvisibleFerret, OtterCookie, JADESNOW, Famous Chollima, Void Dokkaebi, Wagemole, and Tenacious Pungsan. It is best known for fake recruiter outreach, fraudulent job offers, staged technical assessments, and fake interview or troubleshooting workflows that induce victims to execute malicious code. The cluster commonly targets developers through LinkedIn, job platforms, email, code-sharing platforms, and fake company websites. Victims are lured into cloning trojanized repositories, installing malicious packages, opening weaponized projects in development tools, or pasting attacker-supplied commands into a terminal in ClickFix-style flows. Observed delivery mechanisms include malicious npm packages, trojanized coding challenges, fake conferencing or interview software, hidden task automation in developer environments, and browser-based fake update pages. The activity has also expanded beyond classic fake-job lures into broader browsing and malvertising scenarios. Its malware ecosystem is focused on credential theft, cryptocurrency theft, and persistent access. BeaverTail has been used as an infostealer and downloader; InvisibleFerret as a Python-based backdoor and infostealer with remote-access capability; JADESNOW as a JavaScript downloader; and related tooling has included browser-focused stealers, malicious extensions, and remote-access implants. These payloads have targeted browser credentials, cookies, session material, SSH keys, cloud credentials, developer secrets, password-manager data, and cryptocurrency wallets and wallet extensions. Some variants also support keylogging, clipboard theft, reverse shells, remote command execution, and deployment of remote-access software for persistence. A notable tradecraft feature is the use of EtherHiding and other blockchain-backed command-and-control resolution techniques. Operators have used smart contracts on public blockchains, including Ethereum and BNB Smart Chain, to store or retrieve live configuration data and rotate backend infrastructure without changing malware on victim systems. This approach has been observed alongside Node.js, Python, JavaScript, and browser-extension-based payload chains and contributes to resilience against infrastructure disruption. The cluster has also shown sustained software supply-chain activity. Operators have published large numbers of malicious packages to public registries and used trojanized repositories on platforms such as GitHub, GitLab, and Bitbucket. In addition, the actors have monitored cyber threat intelligence platforms and public reporting to identify exposed infrastructure and replace disrupted assets, while continuing to exhibit recurring operational-security failures that exposed parts of their infrastructure and victim workflows. The dominant objective is financial gain for the DPRK regime, particularly through theft of cryptocurrency, wallet material, credentials, and access that can be monetized. Reporting also indicates a secondary espionage dimension through theft of sensitive corporate and developer data and the establishment of footholds in technology environments. The activity overlaps with broader DPRK operations involving fraudulent IT-worker schemes and recruiter impersonation campaigns, but Contagious Interview is primarily distinguished by malware-enabled compromise of developers through fake hiring and technical-evaluation workflows.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this threat actor.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.