WageMole is malware associated with North Korean cyber activity tied to fake job interview and fraudulent IT worker operations. Public reporting cited in the provided content links WageMole to campaigns bearing DPRK hallmarks alongside other malware families including BeaverTail and InvisibleFerret. The malware is referenced in reporting on long-running developer- and job seeker-targeting operations commonly described as Contagious Interview or DeceptiveDevelopment, which used social engineering themes such as recruiting, coding tests, and fake employment workflows. The content also notes a distinction in tradecraft context: some researchers associated WageMole with fake IT worker personas applying to companies, rather than only malicious coding-test repositories. High-confidence attribution in the provided material connects WageMole to North Korean threat activity, with reporting references mentioning Lazarus-linked or DPRK-linked operations and later coverage linking it to North Korean remote worker activity in Western organizations. The provided content does not include specific technical details on WageMole’s internal functionality, persistence, or concrete indicators of compromise.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
Additional Features of OtterCookie Malware Used by WaterPlum ... WageMole
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A named malware/tool referenced in reporting on WaterPlum and Contagious Interview-related activity.
WageMole is a malware campaign or persona associated with North Korean threat actors, involving fake IT workers applying to companies, overlapping with the Contagious Interview campaign.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.