logo

New DPRK Interview Campaign Uses Fake Fonts to Deliver Malware

ID: ac3359b1-18ec-5f25-b911-f5c4fb73bc6d

STIX ID: report--ac3359b1-18ec-5f25-b911-f5c4fb73bc6d

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-26

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**Executive summary:** OpenSourceMalware documents a sustained, high-risk supply-chain campaign (the “Contagious Interview” / “Fake Font” sub-campaign) that lures software developers via fake recruiter GitHub repositories and uses VS Code tasks to silently execute obfuscated JavaScript loaders which fetch and deploy the InvisibleFerret Python backdoor; the malware harvests browser credentials and 13+ cryptocurrency wallet types, achieves persistence across Windows/macOS/Linux, and maintains remote access via WebSockets, with 17 malicious repositories and multiple payload variants identified and attributed to North Korean Lazarus-linked actors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.