Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
BlockNovas has utilized Beavertail and Invisible Ferret malware, as well as employed tactics where applicants are enticed to download and execute malware to solve a fictitious problem with their laptop camera during an automated job interviewing process.
11 distinct techniques documented for this family, organized by ATT&CK tactic.
"Victims... are instructed to clone and execute an NPM package... The executed NPM package directly loads a follow-on payload."
Foreign IT professionals are contacted as part of a common social engineering tactic that involves enticing software developers with fake job interviews. In this scheme, developers apply for positions advertised on platforms like LinkedIn and other recruitment sites.
The malware operates as a lightweight command-and-control beacon... and can execute arbitrary attacker-supplied code by spawning a local runtime and piping the payload directly through standard input.
Invisible Ferret is a Python-based backdoor used in later stages of the attack chain, enabling remote command execution.
"When victims open the downloaded package in Visual Studio Code... If trust is granted, Visual Studio Code automatically executes the repository’s task configuration file, which then fetches and loads the backdoor."
"ultimately persuading victims to execute malicious packages or commands under the guise of routine evaluation tasks"
The supposed recruiter requests the applicant to complete specific tasks as part of the interview process... the applicant must download from reputable code repositories... When the applicant runs the downloaded code... the attacker gains access to the applicant's system.
1 indicator attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Python malware payload referenced as part of Contagious Interview activity in the comparison table.
Python-based backdoor deployed as a follow-on payload after initial access, enabling remote command execution, reconnaissance, and persistent control.
Malware used alongside Beavertail in fake job interview campaigns to infect applicants who are tricked into downloading and executing malicious files.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.