Listen to this Post

The increasing sophistication of cyber-attacks tied to North Korea continues to pose significant challenges for cybersecurity experts. One of the most recent and concerning threats is a new malware campaign known as Contagious Interview, a highly deceptive operation designed to distribute malware through fake job offers. What makes this campaign even more alarming is the use of front companies, fictitious profiles, and cryptocurrency-focused lures to carry out malicious activities.
In this elaborate scam, North Korea-linked threat actors have set up fake companies in the cryptocurrency consulting sector, including BlockNovas LLC, Angeloper Agency, and SoftGlide LLC. These front companies operate primarily as a means to distribute malware via job interviews, an approach known as “social engineering.” Through these lures, the attackers aim to infect potential targets with a range of malware types, including BeaverTail, InvisibleFerret, and OtterCookie, all while masking their true intentions under the guise of legitimate job offers.
Key Findings in the Contagious Interview Campaign
Silent Push, a cybersecurity firm, conducted an in-depth analysis of this malware campaign, identifying the involvement of three main front companies. These fake businesses operate within the cryptocurrency consulting field:
1. BlockNovas LLC (blocknovas[.]com)
2. Angeloper Agency (angeloper[.]com)
3. SoftGlide LLC (softglide[.]co)
These companies target individuals in the tech and cryptocurrency sectors, primarily through job interviews and video assessments. Once an individual engages with these fake companies, they are led to download malicious files under the pretense of coding assignments or fixing browser issues related to video assessments.
The Contagious Interview campaign is part of a broader set of social engineering strategies used by North Korean cyber actors. It operates under various aliases, such as CL-STA-0240, DeceptiveDevelopment, and Famous Chollima, among others. These campaigns have become increasingly complex and difficult to trace, thanks to the attackers’ use of sophisticated anonymization techniques.
How the Malware Propagates
The malware distributed via this scheme is notably diverse, with the attackers using several distinct tools. BeaverTail, a JavaScript stealer and loader, is the initial payload in the attack chain. Once it infects a target’s system, it downloads InvisibleFerret, a Python backdoor that can maintain persistence on a wide range of systems, including Windows, Linux, and macOS.
The InvisibleFerret backdoor grants attackers ongoing access to infected systems, enabling them to harvest sensitive information, download additional malware, and even take control of the system remotely through reverse shells. In some cases, OtterCookie is delivered as an additional payload via the same JavaScript loader.
The BlockNovas front company has also been linked to the deployment of other malware strains, including FROSTYFERRET and GolangGhost, which are distributed through fake job interviews related to ClickFix lures, an extension of the ClickFake Interview campaign.
Deceptive Recruitment and AI Integration
One notable development in the Contagious Interview campaign is the use of AI-powered tools. The attackers have leveraged technologies like Remaker to create fake profile pictures, adding an additional layer of legitimacy to their fraudulent job offers. This makes it harder for targets to discern the malicious intent behind the recruitment process.
Moreover, the use of social media platforms like Facebook, LinkedIn, GitHub, and GitLab to create fake employee personas has become a common tactic. These platforms are exploited to further build the appearance of legitimacy and credibility around the front companies.
In addition to traditional methods of malware distribution, the attackers have also turned to cryptocurrency wallets, with some evidence pointing to the use of tools like Kryptoneer, which connects to Suiet Wallet, Ethos Wallet, and Sui Wallet. These tools may be used to target cryptocurrency investors and steal their digital assets.
What Undercode Say:
This campaign reveals a troubling trend in the use of fake job interviews as a vector for malware distribution. The incorporation of cryptocurrency-related lures, coupled with the use of AI-generated profile images, suggests that North Korean cyber actors are refining their tactics to target specific sectors, including technology and finance. The use of front companies not only allows them to evade detection but also creates an illusion of legitimacy that makes it easier to manipulate potential victims.
Moreover, the use of multi-layered anonymization tactics, such as VPNs and proxies, demonstrates the sophisticated nature of the campaign. The attackers’ ability to mask their operations through such layers, especially using Russian IP ranges, also hints at possible collaborations between North Korea and Russian entities, something that cybersecurity analysts have speculated on in the past.
By leveraging social media platforms, the attackers are also able to extend their reach and convince victims of the legitimacy of the job offers they receive. This further emphasizes the need for organizations and individuals to be cautious when receiving unsolicited job offers, especially in the tech and cryptocurrency fields, which are frequently targeted.
Fact Checker Results:
- Fact 1: The threat actors use multiple layers of obfuscation, including VPNs, proxies, and AI-generated personas to avoid detection.
- Fact 2: The attackers’ main focus seems to be individuals in the cryptocurrency and tech sectors, with tools specifically designed to exploit digital asset vulnerabilities.
- Fact 3: There is strong evidence that some of the infrastructure used in the campaign is shared with Russian entities, raising concerns about international collaboration in cybercrime activities.
References:
Reported By: thehackernews.com
Extra Source Hub:
https://www.quora.com
Wikipedia
Undercode AI
Image Source:
Unsplash
Undercode AI DI v2




