Contagious Interview steps outside the developer workflow

2026-09-03 Jamf

https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers

Thumbnail for Contagious Interview steps outside the developer workflow

Jamf identified 14 trojanized macOS DMG and PKG samples tied to the DPRK-attributed Contagious Interview campaign, extending its delivery methods beyond fake coding tests, Visual Studio Code task files, and Git hooks. The unsigned installers launched legitimate applications as decoys while retrieving a multi-stage chain from 162.0.239.85. Its final OtterCookie payload provided remote access, stole browser and cryptocurrency-wallet credentials, scanned sensitive files, and monitored the clipboard. Shared infrastructure included several domains resolving to the same server, with the payload listener operating on port 3000.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN lalitae.com 2026-09-03 2026-09-03
DOMAIN kikaiverse.com 2026-09-03 2026-09-03
DOMAIN pobel.studio 2026-09-03 2026-09-03
DOMAIN pobelstudio.com 2026-09-03 2026-09-03
DOMAIN softcus.net 2026-09-03 2026-09-03
DOMAIN miniapp.w3pi.social 2026-09-03 2026-09-03
DOMAIN w3pi.social 2026-09-03 2026-09-03
IPv4 162.0.239.85 2026-09-03 2026-09-03

Related Actors

Related Reports

« Back