Contagious Interview | North Korean Threat Actors Reveal Plans and Ops by Abusing Cyber Intel Platforms
ID: 6f111175-3884-5448-b0f7-1e110a6f42d2
STIX ID: report--6f111175-3884-5448-b0f7-1e110a6f42d2
Date Published: 2025-09-04
Date Updated: 2026-07-27
Author: Aleksandar Milenkoski, Sreekar Madabushi (Validin) & Kenneth Kinion (Validin)
## Executive Summary: SentinelLABS and Validin tracked activity from North Korea–aligned actors behind the “Contagious Interview” campaign (also linked to Lazarus) that use a ClickFix social-engineering lure to trick job applicants—mostly in the cryptocurrency sector—into running curl commands that fetch ContagiousDrop malware. The investigation observed coordinated team behavior (likely Slack), active use of CTI platforms (Validin, VirusTotal, Maltrail) to scout and monitor infrastructure, frequent OPSEC failures exposing logs and victim data (over 230 victims observed Jan–Mar 2025), rapid infrastructure churn to replace takedowns, and numerous IOCs (email addresses, domains, IPs, and SHA‑1 hashes) to support defensive action and takedown efforts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
