North Korean threat actors linked to Contagious Interview, Famous Chollima, and Lazarus used fake job and hiring platforms to infect applicants with BeaverTail, InvisibleFerret, FlexibleFerret, FrostyFerret, GolangGhost, and related malware families. Researchers said the operation evolved from earlier job-themed campaigns into ClickFix-style social engineering, where victims were told to copy and paste OS-specific troubleshooting commands from bogus interview sites. The infrastructure collected visitor IP and geolocation data, checked for cryptocurrency wallet browser objects, and then delivered tailored payloads for Windows, macOS, and Linux through staged download chains and fake recruiter workflows.
The campaign expanded beyond software developers to target cryptocurrency, marketing, and other less technical roles, reflecting a broader DPRK shift toward centralized finance and job seekers who may be less suspicious of recruiter outreach. Reports tied the activity to malicious repositories, dozens of weaponized npm packages, fake hiring domains such as businesshire[.]top, and backend infrastructure including nvidiasdk.fly[.]dev, while analysts also documented persistence via Run keys and LaunchAgents, password theft on macOS, and malware loaders designed to frustrate analysis through allowlists and low-volume testing. Security firms assessed the activity as an ongoing evolution of the long-running Contagious Interview operation rather than isolated incidents.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
16 events from the most recent confirmed update back to the earliest known activity.
GitLab reported infrastructure used to distribute BeaverTail and InvisibleFerret variants had been in use since at least May 2025.
GitLab found commit history showing malware files were uploaded to the RominaMabelRamirez/dify GitHub repository by the identity Yash-1511 <yash1511@gmail.com> in late April 2025.
Sekoia said its findings were originally issued in a private FLINT report dated 21 March 2025, describing the Lazarus ClickFake Interview campaign targeting cryptocurrency job seekers with fake interview sites and ClickFix lures.
Sekoia referenced reporting that Lazarus targeted UAE-based crypto exchange Bybit in March 2025, resulting in the theft of $1.5 billion.
SI-CERT published a technical analysis of a social-engineering campaign targeting Web3 companies and individuals via LinkedIn lures and malicious npm packages that deployed BeaverTail and InvisibleFerret. The report detailed the malware's execution chain, data theft and backdoor capabilities, and released indicators including GitHub lure URLs, hashes, and C2 infrastructure.
GitLab reported a 2025 campaign using a fake hiring platform at businesshire[.]top and ClickFix lures to distribute BeaverTail and InvisibleFerret, targeting marketing and cryptocurrency trader roles rather than primarily software developers.
On 18 September 2024, Proofpoint identified a campaign that abused legitimate GitHub notification emails to lure repository owners and collaborators to a fake GitHub site using ClickFix and reCAPTCHA Phish techniques. If victims executed the copied PowerShell command, it downloaded Lumma Stealer; Proofpoint said the campaign impacted at least 300 organizations globally.
HiSolutions investigated a cryptocurrency theft in a software developer environment in fall 2024 and found an intrusion chain matching the North Korea-linked Contagious Interview campaign. The analysis disclosed the Tsunami malware framework, showing BeaverTail and InvisibleFerret leading to a modular payload that used Pastebin accounts and a Tor onion service for command and control.
Sekoia cited Chainalysis estimates that North Korean threat actors stole roughly $1.3 billion from cryptocurrency platforms in 2024, up from $660.5 million in 2023.
Sekoia said Palo Alto documented Contagious Interview in November 2023, establishing public reporting on North Korean job-lure malware activity.
Sekoia reported that the Lazarus-linked Contagious Interview operation had been ongoing since at least December 2022, using fake job opportunities to target victims.
Securonix disclosed that the DEV#POPPER threat actors had retooled their fake job interview operation, using a malicious ZIP package and obfuscated JavaScript to deliver Python-based malware for Windows, Linux, and macOS. The updated malware added capabilities including AnyDesk-based persistence, expanded FTP exfiltration, keylogging, clipboard monitoring, and browser credential and cookie theft, with victims observed across South Korea, North America, Europe, and the Middle East.
Researchers analyzing Lazarus's Contagious Interview campaign described three updated payload-delivery mechanisms for BeaverTail, InvisibleFerret, and OtterCookie, including token-gated Vercel-hosted retrieval and a try/catch-based error-path execution method. The report also published related infrastructure artifacts and IOCs, showing added obfuscation intended to evade static and pattern-based detection.
Sekoia published its investigation into the Lazarus ClickFake Interview campaign, linking it to the broader Contagious Interview operation and detailing Windows and macOS infection chains using ClickFix social engineering.
Walmart Global Tech published an analysis of a Golang backdoor and the macOS payload ChromeUpdateAlert.app used in a fake job interview malware campaign associated with Contagious Interview activity. The report detailed fake interview infrastructure, Dropbox OAuth-based data exfiltration from the macOS app, and published related domains, IPs, and other indicators of compromise.
A Socket blog reference indicates reporting on an escalation of the Contagious Interview campaign involving 67 malicious npm packages and a new malware loader.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
17 references tracked. Mallory keeps watching after this page renders.
securonix.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceblog.daviddodda.com
Open sourcegitlab-com.gitlab.io
Open sourceunit42.paloaltonetworks.com
Open sourceregular-expressions.info
Open sourcegroup-ib.com
Open sourcemalpedia.caad.fkie.fraunhofer.de
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.