Contagious Interview steps outside the developer workflow
2026-09-03 • Jamf •
https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers
Jamf identified 14 trojanized macOS DMG and PKG samples tied to the DPRK-attributed Contagious Interview campaign, extending its delivery methods beyond fake coding tests, Visual Studio Code task files, and Git hooks. The unsigned installers launched legitimate applications as decoys while retrieving a multi-stage chain from 162.0.239.85. Its final OtterCookie payload provided remote access, stole browser and cryptocurrency-wallet credentials, scanned sensitive files, and monitored the clipboard. Shared infrastructure included several domains resolving to the same server, with the payload listener operating on port 3000.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | lalitae.com | 2026-09-03 | 2026-09-03 |
| DOMAIN | kikaiverse.com | 2026-09-03 | 2026-09-03 |
| DOMAIN | pobel.studio | 2026-09-03 | 2026-09-03 |
| DOMAIN | pobelstudio.com | 2026-09-03 | 2026-09-03 |
| DOMAIN | softcus.net | 2026-09-03 | 2026-09-03 |
| DOMAIN | miniapp.w3pi.social | 2026-09-03 | 2026-09-03 |
| DOMAIN | w3pi.social | 2026-09-03 | 2026-09-03 |
| IPv4 | 162.0.239.85 | 2026-09-03 | 2026-09-03 |