How DPRK’s Contagious Interview Campaign Targets Developers
ID: 3197c3fe-4b66-577d-8fa3-417436de5c25
STIX ID: report--3197c3fe-4b66-577d-8fa3-417436de5c25
Feed Name: Kudelski Security
Kudelski Security details a DPRK-linked campaign (“Contagious Interview”) where operators impersonate recruiters to coerce developers into running a trojanized GitHub project or opening a malicious .vscode/tasks.json, which installs an obfuscated Node.js backdoor that collects system info, exfiltrates environment variables and secrets, beacons to a Hetzner-hosted C2 (e.g. http://138.201.128.169:1224/api/...), supports remote code execution and session tracking, and leverages proxies/VPNs and Nircmd for hidden execution; the report includes IOCs and Suricata/YARA detection guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
