Another Wave: North Korean Contagious Interview Campaign Dro...
Blog post from Socket
In a recent development, North Korean threat actors linked to the Contagious Interview campaign have launched a sophisticated supply chain attack using 35 new malicious npm packages, which have been downloaded over 4,000 times. These packages, often distributed through social engineering tactics on LinkedIn, contain a multi-stage malware loader, HexEval, that collects host metadata and deploys the BeaverTail infostealer, which is linked to the Democratic People’s Republic of Korea (DPRK). The operation is characterized by its stealth, using typosquatting and fake recruiter profiles to lure software developers into downloading and executing the malicious code, often bypassing containerized environments for deeper system penetration. BeaverTail and its third-stage backdoor, InvisibleFerret, enable the attackers to steal sensitive data and maintain persistent access across various operating systems. The campaign's complexity and real-time adaptation highlight the evolving tradecraft of North Korean cyber threats, emphasizing the need for enhanced security measures beyond traditional static analysis to protect against such sophisticated attacks.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.