The Contagious Interview: How NICKEL ALLEY Turns Your “Dream Job” into a North Korean Crypto Nightmare
ID: 773b3b16-1db8-5fec-bb10-d528373b1f90
STIX ID: report--773b3b16-1db8-5fec-bb10-d528373b1f90
Feed Name: securityonline.info
Sophos CTU reports that NICKEL ALLEY, a North Korean-linked threat group, is conducting sophisticated 'Contagious Interview' campaigns targeting tech professionals through fake job offers and interview sites; victims are tricked into running commands or cloning repositories (npm install/start) that deploy PyLangGhost RAT and other malware via techniques such as ClickFix and malicious .vscode/tasks.json, enabling credential and crypto wallet theft, file exfiltration, and potential supply-chain compromise. Organizations are advised to monitor suspicious command execution (curl/PowerShell from %TEMP%), watch Node.js-originating network traffic, and report unsolicited recruitment lures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
