#FakeFont
Incident/Operation
2026-01-28 • New DPRK Contagious Interview Campaign: “Fake Font” Uses Malicious VSCode Fonts
Fake Font is a subcampaign of the DPRK-linked Contagious Interview activity that targeted software engineers through fraudulent recruiters and malicious coding assessments. Active for more than 100 days by late January 2026, it distributed weaponized repositories that abused Visual Studio Code task automation to execute JavaScript disguised as web-font files. The multistage chain ultimately installed the InvisibleFerret Python backdoor for persistent access and theft of browser credentials and cryptocurrency-wallet data.
-
1
Tagged Reports
-
1
Unique Authors
-
1
Active Days