북한 위협 행위자 Contagious Interview 캠페인 분석(2보)

2025-05-13 Igloo Contagious Interview

https://www.igloopedia.com/1edf216a-760c-80ef-8341-fe6774dc1467

Thumbnail for 북한 위협 행위자 Contagious Interview 캠페인 분석(2보)

The report covers additional Contagious Interview activity in which North Korean threat actors expanded BeaverTail distribution beyond npm and GitHub to Bitbucket. Malicious npm packages were used to target software developers, sometimes through fake job-assessment workflows or typosquatting, and some shared C2 infrastructure with Phantom Circuit activity. The BeaverTail payload steals browser data, cryptocurrency wallet extension data, Solana keypair stores, Firefox extension data, macOS keychain material, and browser login databases. It can also download and execute Invisible Ferret, and the report notes evolving evasion through hex-encoded C2 data, staging services, obfuscation, and anti-debugging logic.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 45.61.151.71 2025-04-04 2025-11-13
IPv4 172.86.84.38 2025-03-10 2025-11-13
IPv4 185.153.182.241 2025-01-29 2025-11-13
IPv4 86.104.74.51 2024-12-03 2025-11-13
HASH 35259b4caa400e4d663069a7f32f0138 2025-05-13 2025-05-13
HASH 53faeba2887693d8810c58f7ca13041f 2025-05-13 2025-05-13
HASH 51bd561c3a476662f985710c2f17c093 2025-05-13 2025-05-13
HASH 37c14026d60c7488e39136d9ed6b47e9 2025-05-13 2025-05-13
HASH 5d2dae18af58b25aecdd7b21ec24ce81 2025-05-13 2025-05-13
HASH a7e5334e37358902442c891e5d0008f8 2025-05-13 2025-05-13
HASH 484ff14e1532d43c92c8e2911f35f5c6 2025-05-13 2025-05-13
HASH 98a8d1c6fc75fcf0c8cc8ae45edb387f 2025-05-13 2025-05-13
HASH 839fe5b6de8dee3f25c9a393f6f38310 2025-05-13 2025-05-13
HASH 1593447fc915c3e26ea301e959f4e182 2025-05-13 2025-05-13
HASH b30ad48b17e7191062fc47c9803b960f 2025-05-13 2025-05-13
HASH 464b8bf3a3047833edf3dd35b4a35053 2025-05-13 2025-05-13
HASH 7eb685fd9f3898577ee3082cedb29510 2025-05-13 2025-05-13
HASH afefc11502dfcb3696e6028c5c6fc36c 2025-05-13 2025-05-13
URL https://ip-api-server.vercel.ap… 2025-05-13 2025-05-13
URL https://ip-api-server.vercel.ap… 2025-05-13 2025-05-13
URL https://ip-api-server.vercel.ap… 2025-05-13 2025-05-13
IPv4 144.172.96.80 2025-05-13 2025-05-13
URL https://m21gk.wiremockapi.cloud… 2025-04-04 2025-05-13
URL https://mocki.io/v1/32f16c80-60… 2025-04-04 2025-05-13
DOMAIN m21gk.wiremockapi.cloud 2025-04-04 2025-05-13
IPv4 144.172.86.27 2025-03-17 2025-05-13
IPv4 94.131.9.32 2025-01-29 2025-05-13

Related Actors

Related Reports

« Back