PurpleBravo’s Targeting of the IT Software Supply Chain
ID: e067ff2c-8d52-5397-9b3a-48aff83f2930
STIX ID: report--e067ff2c-8d52-5397-9b3a-48aff83f2930
Feed Name: Recorded Future Blog
Insikt Group / Recorded Future detail the PurpleBravo (Contagious Interview) campaign — a North Korean state‑linked operation that impersonates recruiters to target developers (notably in cryptocurrency and South Asia) and deliver malicious GitHub-hosted JavaScript and RATs. The report analyzes multiple malware families (BeaverTail infostealer; PylangGhost/GolangGhost RATs with advanced Chrome credential decryption; InvisibleFerret multi‑platform RAT), enumerates C2 infrastructure and thousands of likely targets, documents overlap with PurpleDelta actors, and provides IoCs and mitigations to reduce supply‑chain and credential‑theft risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
