logo

Contagious Interview Actors Now Utilize JSON Storage Services for Malware Delivery

ID: deef3861-43a5-5b37-aff0-f88163821a06

STIX ID: report--deef3861-43a5-5b37-aff0-f88163821a06

Feed Name: NVISO Labs

Threat Score
85/100

Date Published: 2025-11-13

Date Updated: 2026-05-18

Author: Bart Parys

...
...

NVISO describes the Contagious Interview campaign attributed to DPRK-aligned actors who social-engineer developers with fake recruiter interviews and trojanized demo projects; they abuse legitimate JSON storage services and code repositories to host obfuscated JavaScript/Python that delivers BeaverTail infostealer, InvisibleFerret RAT, and Tsunami components for data and crypto-wallet exfiltration, persistence, and further payload retrieval, and the report includes detailed TTPs and extensive IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.