DPRK's Contagious Interview campaign is still running

2026-08-14 Moonlock

https://x.com/moonlock_lab/status/2088333062153138563

Thumbnail for DPRK's Contagious Interview campaign is still running

Moonlock Lab analyzed an active Contagious Interview chain targeting macOS users with a fake Git helper shell script that downloads a Node.js runner and an obfuscated OtterCookie payload. The payload steals browser passwords and Keychain data, scans files and clipboard contents, targets 40 cryptocurrency wallet extensions, and provides remote shell and file-access capabilities. Three workers beacon to 104.194.153.144, while the lure infrastructure uses githelper.store. Researchers said the payload's comments and inconsistent construction suggest increasing use of AI-generated code, although this remains an assessment rather than a proven development method.

Indicators of Compromise

Type Value First Seen Last Seen
HASH f3c95dc199b343875bd2b66be43091c… 2026-08-14 2026-08-14
HASH 4cd973b787d5a489a5281adfa0ab02e… 2026-08-14 2026-08-14
HASH 9fe86f0b19fb4d6ac47100f72a9b7f0… 2026-08-14 2026-08-14
HASH cc92280557b399ec9271af08c5b6f57… 2026-08-14 2026-08-14
HASH a8d61b58e99a4bfd549aeb4eb9499cf… 2026-08-14 2026-08-14
IPv4 104.194.153.144 2026-08-14 2026-08-14
DOMAIN githelper.store 2026-08-14 2026-08-14

Related Actors

Related Reports

« Back