북한 위협 행위자 Contagious Interview 캠페인 분석(2보)
2025-05-13 • Igloo • Contagious Interview •
https://www.igloopedia.com/1edf216a-760c-80ef-8341-fe6774dc1467
The report covers additional Contagious Interview activity in which North Korean threat actors expanded BeaverTail distribution beyond npm and GitHub to Bitbucket. Malicious npm packages were used to target software developers, sometimes through fake job-assessment workflows or typosquatting, and some shared C2 infrastructure with Phantom Circuit activity. The BeaverTail payload steals browser data, cryptocurrency wallet extension data, Solana keypair stores, Firefox extension data, macOS keychain material, and browser login databases. It can also download and execute Invisible Ferret, and the report notes evolving evasion through hex-encoded C2 data, staging services, obfuscation, and anti-debugging logic.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| IPv4 | 45.61.151.71 | 2025-04-04 | 2025-11-13 |
| IPv4 | 172.86.84.38 | 2025-03-10 | 2025-11-13 |
| IPv4 | 185.153.182.241 | 2025-01-29 | 2025-11-13 |
| IPv4 | 86.104.74.51 | 2024-12-03 | 2025-11-13 |
| HASH | 35259b4caa400e4d663069a7f32f0138 | 2025-05-13 | 2025-05-13 |
| HASH | 53faeba2887693d8810c58f7ca13041f | 2025-05-13 | 2025-05-13 |
| HASH | 51bd561c3a476662f985710c2f17c093 | 2025-05-13 | 2025-05-13 |
| HASH | 37c14026d60c7488e39136d9ed6b47e9 | 2025-05-13 | 2025-05-13 |
| HASH | 5d2dae18af58b25aecdd7b21ec24ce81 | 2025-05-13 | 2025-05-13 |
| HASH | a7e5334e37358902442c891e5d0008f8 | 2025-05-13 | 2025-05-13 |
| HASH | 484ff14e1532d43c92c8e2911f35f5c6 | 2025-05-13 | 2025-05-13 |
| HASH | 98a8d1c6fc75fcf0c8cc8ae45edb387f | 2025-05-13 | 2025-05-13 |
| HASH | 839fe5b6de8dee3f25c9a393f6f38310 | 2025-05-13 | 2025-05-13 |
| HASH | 1593447fc915c3e26ea301e959f4e182 | 2025-05-13 | 2025-05-13 |
| HASH | b30ad48b17e7191062fc47c9803b960f | 2025-05-13 | 2025-05-13 |
| HASH | 464b8bf3a3047833edf3dd35b4a35053 | 2025-05-13 | 2025-05-13 |
| HASH | 7eb685fd9f3898577ee3082cedb29510 | 2025-05-13 | 2025-05-13 |
| HASH | afefc11502dfcb3696e6028c5c6fc36c | 2025-05-13 | 2025-05-13 |
| URL | https://ip-api-server.vercel.ap… | 2025-05-13 | 2025-05-13 |
| URL | https://ip-api-server.vercel.ap… | 2025-05-13 | 2025-05-13 |
| URL | https://ip-api-server.vercel.ap… | 2025-05-13 | 2025-05-13 |
| IPv4 | 144.172.96.80 | 2025-05-13 | 2025-05-13 |
| URL | https://m21gk.wiremockapi.cloud… | 2025-04-04 | 2025-05-13 |
| URL | https://mocki.io/v1/32f16c80-60… | 2025-04-04 | 2025-05-13 |
| DOMAIN | m21gk.wiremockapi.cloud | 2025-04-04 | 2025-05-13 |
| IPv4 | 144.172.86.27 | 2025-03-17 | 2025-05-13 |
| IPv4 | 94.131.9.32 | 2025-01-29 | 2025-05-13 |