Contagious Interview is a North Korea-aligned threat activity cluster centered on social-engineering software developers and job seekers, especially individuals involved in cryptocurrency, blockchain, and broader technology roles. The operation is widely associated with UNC5342 and has also been linked in overlapping reporting to aliases and malware families including BeaverTail, InvisibleFerret, OtterCookie, JADESNOW, Famous Chollima, Void Dokkaebi, Wagemole, and Tenacious Pungsan. It is best known for fake recruiter outreach, fraudulent job offers, staged technical assessments, and fake interview or troubleshooting workflows that induce victims to execute malicious code. The cluster commonly targets developers through LinkedIn, job platforms, email, code-sharing platforms, and fake company websites. Victims are lured into cloning trojanized repositories, installing malicious packages, opening weaponized projects in development tools, or pasting attacker-supplied commands into a terminal in ClickFix-style flows. Observed delivery mechanisms include malicious npm packages, trojanized coding challenges, fake conferencing or interview software, hidden task automation in developer environments, and browser-based fake update pages. The activity has also expanded beyond classic fake-job lures into broader browsing and malvertising scenarios. Its malware ecosystem is focused on credential theft, cryptocurrency theft, and persistent access. BeaverTail has been used as an infostealer and downloader; InvisibleFerret as a Python-based backdoor and infostealer with remote-access capability; JADESNOW as a JavaScript downloader; and related tooling has included browser-focused stealers, malicious extensions, and remote-access implants. These payloads have targeted browser credentials, cookies, session material, SSH keys, cloud credentials, developer secrets, password-manager data, and cryptocurrency wallets and wallet extensions. Some variants also support keylogging, clipboard theft, reverse shells, remote command execution, and deployment of remote-access software for persistence. A notable tradecraft feature is the use of EtherHiding and other blockchain-backed command-and-control resolution techniques. Operators have used smart contracts on public blockchains, including Ethereum and BNB Smart Chain, to store or retrieve live configuration data and rotate backend infrastructure without changing malware on victim systems. This approach has been observed alongside Node.js, Python, JavaScript, and browser-extension-based payload chains and contributes to resilience against infrastructure disruption. The cluster has also shown sustained software supply-chain activity. Operators have published large numbers of malicious packages to public registries and used trojanized repositories on platforms such as GitHub, GitLab, and Bitbucket. In addition, the actors have monitored cyber threat intelligence platforms and public reporting to identify exposed infrastructure and replace disrupted assets, while continuing to exhibit recurring operational-security failures that exposed parts of their infrastructure and victim workflows. The dominant objective is financial gain for the DPRK regime, particularly through theft of cryptocurrency, wallet material, credentials, and access that can be monetized. Reporting also indicates a secondary espionage dimension through theft of sensitive corporate and developer data and the establishment of footholds in technology environments. The activity overlaps with broader DPRK operations involving fraudulent IT-worker schemes and recruiter impersonation campaigns, but Contagious Interview is primarily distinguished by malware-enabled compromise of developers through fake hiring and technical-evaluation workflows.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Attributed origin per open-source reporting.
54 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
38 malware families attributed to this actor across reporting.
33 additional families tracked in Mallory.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
"A critical remote code execution (RCE) vulnerability, identified as CVE-2025-55182 and dubbed React2Shell, exists within the React Server Components (RSC) architecture, allowing unauthenticated attackers to execute arbitrary code..."
This detection identifies instances where Windows Explorer.exe spawns PowerShell or cmd.exe processes, particularly focusing on executions initiated by LNK files. This behavior is associated with the ZDI-CAN-25373 Windows shortcut zero-day vulnerability, where specially crafted LNK files are used to trigger malicious code execution through cmd.exe or powershell.exe. This technique has been actively exploited by multiple APT groups in targeted attacks through both HTTP and SMB delivery methods.
553 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
North Korean-associated activity linked to a macOS malware campaign using fake update screens and ClickFix-style social engineering to steal cryptocurrency wallets, browser data, and developer credentials.
Referenced as a named activity cluster in a post about ClickFix, EtherHiding, and a DPRK wallet trail.
Conducting a sophisticated macOS malvertising and social-engineering campaign that redirects users to fake update pages, tricks them into pasting a malicious command into Terminal, deploys a Node.js backdoor with LaunchAgent persistence, uses EtherHiding via Ethereum smart contracts for resilient C2 resolution, and delivers an information stealer plus a malicious Chrome extension aimed at cryptocurrency theft.
DPRK-linked financially motivated intrusion activity using ClickFix-style fake macOS update lures, a Node.js backdoor, Ethereum smart-contract-based EtherHiding C2, credential and cryptocurrency theft, and a malicious Chrome extension tied to crypto theft and laundering.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.