Contagious Interview

2023-11-21 • Paloalto NetworksContagious Interview: DPRK Threat Actors Lure Tec…

Contagious Interview is the name Palo Alto Networks' Unit 42 gave in November 2023 to an ongoing campaign, tracked internally as CL-STA-0240, that Unit 42 attributes with moderate confidence to a North Korea state-sponsored threat actor. Unit 42 found the activity, dating to at least December 2022, poses as employers offering software development jobs, luring victims through fake interviews into installing malicious npm packages hosted on GitHub; this delivers malware Unit 42 named BeaverTail, a cross-platform information stealer and loader, followed by a Python backdoor named InvisibleFerret, with an objective of cryptocurrency theft and establishing footholds for further attacks. Unit 42 has continued to track the campaign's evolution, including a cross-platform BeaverTail variant compiled with the Qt framework in mid-2024. Other researchers, including Datadog, have linked additional malicious npm packages and distinct threat-actor clusters, such as one Datadog separately named Tenacious Pungsan, to the same Contagious Interview activity targeting software and blockchain developers.

Related Actors

Related Reports

Top Authors

View all reports in this cluster

View all reports in this cluster