news.mlab.sh
Threat intelligence
Threat actor

Operation Contagious Interview

Profile from actors.mlab.sh, coverage from our own index.

Suspected origin
North Korea
TLP
WHITE

A subgroup of Lazarus Group, Hidden Cobra, Labyrinth Chollima. (Palo Alto) Unit 42 researchers recently discovered two separate campaigns targeting job-seeking activities linked to state-sponsored threat actors associated with the Democratic People’s Republic of Korea (DPRK), commonly known as North Korea. We call the first campaign “Contagious Interview,” where threat actors pose as employers (often anonymously or with vague identities) to lure software developers into installing malware through the interview process. This malware creates the potential for various types of theft. We attribute with moderate confidence that Contagious Interview is run by a North Korea state-sponsored threat actor. We call the second campaign “Wagemole,” where threat actors seek unauthorized employment with organizations based in the US and other parts of the world, with potential for both financial gain and espionage. We attribute with high confidence that Wagemole is a North Korea state-sponsored threat. Activity from both campaigns remains an ongoing active threat.

Also known as

Contagious InterviewDeceptiveDevelopmentDEV#POPPERGwisin GangJasper SleetNickel TapestryPurpleBravoStorm-0287TAG-121Tenacious PungsanUNC5267WagemoleWaterPlum

Tooling and malware

BeaverTailHexEval LoaderInvisibleFerretXORIndex Loader

MITRE ATT&CK techniques

T1090 ProxyT1571 Non-Standard PortT1685 Disable or Modify ToolsT1082 System Information DiscoveryT1083 File and Directory DiscoveryT1041 Exfiltration Over C2 ChannelT1567 Exfiltration Over Web ServiceT1657 Financial TheftT1589 Gather Victim Identity InformationT1593 Search Open Websites/DomainsT1681 Search Threat Vendor DataT1583 Acquire InfrastructureT1585 Establish AccountsT1587 Develop CapabilitiesT1036 MasqueradingT1480 Execution GuardrailsT1497 Virtualization/Sandbox Evasion

Coverage 5