New DPRK Interview Campaign Uses Fake Fonts to Deliver Malware
ID: ac3359b1-18ec-5f25-b911-f5c4fb73bc6d
STIX ID: report--ac3359b1-18ec-5f25-b911-f5c4fb73bc6d
Feed Name: GBHackers
**Executive summary:** OpenSourceMalware documents a sustained, high-risk supply-chain campaign (the “Contagious Interview” / “Fake Font” sub-campaign) that lures software developers via fake recruiter GitHub repositories and uses VS Code tasks to silently execute obfuscated JavaScript loaders which fetch and deploy the InvisibleFerret Python backdoor; the malware harvests browser credentials and 13+ cryptocurrency wallet types, achieves persistence across Windows/macOS/Linux, and maintains remote access via WebSockets, with 17 malicious repositories and multiple payload variants identified and attributed to North Korean Lazarus-linked actors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
