logo

How DPRK’s Contagious Interview Campaign Targets Developers

ID: 3197c3fe-4b66-577d-8fa3-417436de5c25

STIX ID: report--3197c3fe-4b66-577d-8fa3-417436de5c25

Feed Name: Kudelski Security

Threat Score
85/100

Date Published: 2026-06-30

Date Updated: 2026-07-22

...
...

Kudelski Security details a DPRK-linked campaign (“Contagious Interview”) where operators impersonate recruiters to coerce developers into running a trojanized GitHub project or opening a malicious .vscode/tasks.json, which installs an obfuscated Node.js backdoor that collects system info, exfiltrates environment variables and secrets, beacons to a Hetzner-hosted C2 (e.g. http://138.201.128.169:1224/api/...), supports remote code execution and session tracking, and leverages proxies/VPNs and Nircmd for hidden execution; the report includes IOCs and Suricata/YARA detection guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.