logo

PurpleBravo’s Targeting of the IT Software Supply Chain

ID: e067ff2c-8d52-5397-9b3a-48aff83f2930

STIX ID: report--e067ff2c-8d52-5397-9b3a-48aff83f2930

Feed Name: Recorded Future Blog

Threat Score
90/100

Date Published: 2026-01-21

Date Updated: 2026-04-29

...
...

Insikt Group / Recorded Future detail the PurpleBravo (Contagious Interview) campaign — a North Korean state‑linked operation that impersonates recruiters to target developers (notably in cryptocurrency and South Asia) and deliver malicious GitHub-hosted JavaScript and RATs. The report analyzes multiple malware families (BeaverTail infostealer; PylangGhost/GolangGhost RATs with advanced Chrome credential decryption; InvisibleFerret multi‑platform RAT), enumerates C2 infrastructure and thousands of likely targets, documents overlap with PurpleDelta actors, and provides IoCs and mitigations to reduce supply‑chain and credential‑theft risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.