North Korean remote workers landing jobs in the West
ID: 53fb14b1-f35d-5c02-9e4f-91b5a940d86e
STIX ID: report--53fb14b1-f35d-5c02-9e4f-91b5a940d86e
Feed Name: Zscaler Security Research Blog
This report documents the Contagious Interview campaign and related WageMole operations: attackers post fake job opportunities to deliver malicious code (BeaverTail) that stages a Python backdoor (InvisibleFerret) capable of keylogging, stealing browser and cryptocurrency wallet data, compressing/encrypting exfiltrated files, and communicating with C2 via HTTP/Telegram; the campaign is cross-platform, actively developed, has compromised over 140 developers worldwide, and is used both for data theft and to facilitate monetization via fraudulent employment and fund transfers.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
