Contagious Interview, also tracked as UNC5342, is a North Korea-linked, Lazarus Group-associated cyber-espionage and financially motivated campaign that targets developers, job seekers, and cryptocurrency-focused users. It commonly uses fake recruiter contacts, fraudulent coding assessments, and malicious source-code repositories to induce victims to execute attacker-controlled code. Recent activity has also used compromised or deceptive websites, sponsored-search malvertising, and ClickFix-style fake macOS update screens that persuade users to run commands in Terminal.
The campaign employs staged payload delivery across macOS, Windows, and Linux. Observed loaders and backdoors can establish persistence on macOS, retrieve command-and-control configuration through blockchain-based dead-drop infrastructure, execute attacker-supplied code, and download further payloads. Contagious Interview-related infections have delivered information stealers that collect browser data, SSH keys, cloud-service and package-publisher credentials, and cryptocurrency-wallet data. Malicious browser extensions and wallet tampering have also been used to steal cryptocurrency.
Developer-focused variants have embedded loaders in project resources and Git hooks so execution can occur during ordinary repository use, including source-control operations. The campaign uses environment and runtime validation, geolocation-aware payload delivery, and attempts to defeat container isolation. Its infrastructure and social-engineering workflow support scalable targeting of developers, particularly those involved in crypto, DeFi, and web3 projects.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
The OpenSourceMalware team discovered a fresh twist in the DPRK Lazarus Group Contagious Interview / TaskJacker playbook. Operators are hiding their stage-2 loader inside Git hooks... It's the same Contagious Interview social engineering — fake recruiter, "coding assessment" repo, multi-stage loader pulling InvisibleFerret-style implants for crypto wallet and credential theft...
75 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A trojanized macOS-installer campaign referenced in a post linking to a Jamf analysis. The content provides no further behavioral or targeting details.
DPRK-linked malware operation targeting macOS users via malvertising, fake full-screen macOS update pages, and ClickFix-style clipboard poisoning to trick victims into executing a Terminal command that downloads a Node.js backdoor and follow-on payloads.
A Lazarus-associated campaign described as the broader or parallel operation from which PolinRider continues or derives.
A North Korea-linked cross-ecosystem campaign spanning npm, PyPI, Go, Rust, and Packagist that delivered staged RAT payloads through software package ecosystems.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.