North Korean Hackers Exploit Code Repositories in “Contagious Interview” Campaign
ID: f4a1144d-4a9e-53bd-b567-4dbea3fa8571
STIX ID: report--f4a1144d-4a9e-53bd-b567-4dbea3fa8571
Feed Name: GBHackers
Threat Score
SEAL details the "Contagious Interview" campaign attributed to DPRK actors that weaponises code-repository lures and VS Code task hooks to deploy a dual Node.js/Python infostealer and RAT, exfiltrating credentials and cryptocurrency wallets (and deploying an XMRig miner); multiple victims with financial losses and concrete IOCs/TTPs are documented, and recommended mitigations include disabling automatic VS Code tasks, enforcing workspace trust, and scanning for hidden artefacts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
